MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55e287e19b6c08d2555133320f79df24db4ef1f09649f014a5817f890faf7473. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 55e287e19b6c08d2555133320f79df24db4ef1f09649f014a5817f890faf7473
SHA3-384 hash: 18a3bceb0a713272f7656d64cd6418f0981cd8db3e1b93ef1b2d80ebfba9c7f67a38303c6ea957d09fdbd94691fbca24
SHA1 hash: d324b2ecfc4c2ed012692182d7bfa8076577b55a
MD5 hash: a39263133644b7563e4ce346ffa96a90
humanhash: yankee-mexico-pip-lake
File name:Scan_00210.img
Download: download sample
Signature AsyncRAT
File size:96'256 bytes
First seen:2022-04-12 06:37:41 UTC
Last seen:2022-04-12 06:37:55 UTC
File type: img
MIME type:application/x-iso9660-image
ssdeep 384:pni/7h7+loct/n7kXHwVJffffft+SnJyXnLHHJCU8rUUvYxqS/T+zRmhmq3jb344:p4UewcW0LHB8rUUGruTgDYo
TLSH T19E9328D66B540B22CDE9073648E253301B77ED45AAF3EB0B789C72551F73F404682BAA
Reporter cocaman
Tags:AsyncRAT img


Avatar
cocaman
Malicious email (T1566.001)
From: ""Megan Tarpley" <megan.n.tarpley@wellsfargoadvisors.com>" (likely spoofed)
Received: "from mail.johnburch.co.uk (host-92-27-6-45.static.as13285.net [92.27.6.45]) "
Date: "12 Apr 2022 00:16:38 +0200"
Subject: "WIRE Transfer Notification From Wells Fargo Advisors"
Attachment: "Scan_00210.img"

Intelligence


File Origin
# of uploads :
2
# of downloads :
183
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
installutil.exe obfuscated packed
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-04-12 05:21:06 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
14 of 41 (34.15%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

img 55e287e19b6c08d2555133320f79df24db4ef1f09649f014a5817f890faf7473

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments