MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 565f20690f68d19eaee415f2e49808781dd219cffe4f1ad09a82fe16f88ea066. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 565f20690f68d19eaee415f2e49808781dd219cffe4f1ad09a82fe16f88ea066 |
|---|---|
| SHA3-384 hash: | b9d70105d19e75227b89a71b142302f6290a9f3e6a781bc413a8eebb7c3f0f1c8cf2582a81ea0b3ef37f272c52eab07b |
| SHA1 hash: | 71146e3c60724dfa492f3e5f895027b4fbabed55 |
| MD5 hash: | feff2faecf0f98991308eddd4baedf29 |
| humanhash: | item-october-illinois-equal |
| File name: | G.I gratings-pdf.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 9'650 bytes |
| First seen: | 2021-03-02 08:04:05 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 192:oPgePaaYygUlEIQg7MKH75fxkm+rog4OhFP4nMtU2BUc4SYdd/1vjl:o/YyC5255km+rmQ4Me22c4dzbl |
| TLSH | 8112AE79171835E8D35DB8016937AB823F27FC83977A7C448A409DEA91B2171B92CB26 |
| Reporter | |
| Tags: | gz |
abuse_ch
Malspam distributing unidentified malware:HELO: taymer.com
Sending IP: 103.99.1.140
From: info@taymer.com
Subject: Re: Re: R.F.Q
Attachment: G.I gratings-pdf.gz (contains "G.I gratings-pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.