MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 555f841a0d1579dcdf470e62137401d26a8f52155ae9ffde8f19f9360df61d1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 555f841a0d1579dcdf470e62137401d26a8f52155ae9ffde8f19f9360df61d1e
SHA3-384 hash: 5cac9deab2cf8adffc35a87ee1717857d417f6a06b38d4905d030695e6151b058ab0e0950ff3f7dd1d6099c55b580154
SHA1 hash: 7607f50e6c7439f6b450c90ced0b75fcf272b4b2
MD5 hash: 6ed2c465769486acf3dc77006d75eed8
humanhash: cold-equal-december-october
File name:NEW_PURCHASE_ORDER_05_09_202_PDF.IMG
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2020-09-06 05:27:17 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:Wek1PFaP5khXl4ZRM0g42Ohsp/HXnN2hXGGZdSrDPl54RwZ9YciDfkfGxCHP7r9O:Wl14x2p/H3k2GjSrD9aw7YciMfT1q
TLSH F265BE81EA985BA0DCA8A7B4653ADC3043337DBDA974D51C2CCD3DAB3BBB7921021517
Reporter cocaman
Tags:AgentTesla img


Avatar
cocaman
Malicious email
From: "Hussain Kadir" <reigaconsultgbr@gmail.com>
Received: from 357359-cw43190.tmweb.ru (357359-cw43190.tmweb.ru [109.68.213.212])
Date: Sat, 05 Sep 2020 13:51:48 -0400
Subject: RE: NEW Purchase Order_05_09_2020
Attachment: NEW_PURCHASE_ORDER_05_09_202_PDF.IMG

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-09-05 14:26:52 UTC
File Type:
Binary (Archive)
Extracted files:
47
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 555f841a0d1579dcdf470e62137401d26a8f52155ae9ffde8f19f9360df61d1e

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments