MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 555f841a0d1579dcdf470e62137401d26a8f52155ae9ffde8f19f9360df61d1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 555f841a0d1579dcdf470e62137401d26a8f52155ae9ffde8f19f9360df61d1e |
|---|---|
| SHA3-384 hash: | 5cac9deab2cf8adffc35a87ee1717857d417f6a06b38d4905d030695e6151b058ab0e0950ff3f7dd1d6099c55b580154 |
| SHA1 hash: | 7607f50e6c7439f6b450c90ced0b75fcf272b4b2 |
| MD5 hash: | 6ed2c465769486acf3dc77006d75eed8 |
| humanhash: | cold-equal-december-october |
| File name: | NEW_PURCHASE_ORDER_05_09_202_PDF.IMG |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'441'792 bytes |
| First seen: | 2020-09-06 05:27:17 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:Wek1PFaP5khXl4ZRM0g42Ohsp/HXnN2hXGGZdSrDPl54RwZ9YciDfkfGxCHP7r9O:Wl14x2p/H3k2GjSrD9aw7YciMfT1q |
| TLSH | F265BE81EA985BA0DCA8A7B4653ADC3043337DBDA974D51C2CCD3DAB3BBB7921021517 |
| Reporter | |
| Tags: | AgentTesla img |
cocaman
Malicious emailFrom: "Hussain Kadir" <reigaconsultgbr@gmail.com>
Received: from 357359-cw43190.tmweb.ru (357359-cw43190.tmweb.ru [109.68.213.212])
Date: Sat, 05 Sep 2020 13:51:48 -0400
Subject: RE: NEW Purchase Order_05_09_2020
Attachment: NEW_PURCHASE_ORDER_05_09_202_PDF.IMG
Intelligence
File Origin
# of uploads :
1
# of downloads :
132
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-09-05 14:26:52 UTC
File Type:
Binary (Archive)
Extracted files:
47
AV detection:
13 of 48 (27.08%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Eldorado
Score:
0.90
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.