MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d9a4ea6dfc1910c1cdcd6d98c0a4c10a97c34f69f0f0ed7071376dd23ae4b41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5d9a4ea6dfc1910c1cdcd6d98c0a4c10a97c34f69f0f0ed7071376dd23ae4b41
SHA3-384 hash: 786b4749d305119bd8d6484469de1dbb0f563b31bbf5cd868560c7d83606ef57bdfd4cfea64637e5975697b65ae5415b
SHA1 hash: 7e489267636ffc7aa462dfa63f2df72a8bc5cd5e
MD5 hash: f5d5ad7b4e6b666209534f6d082eab70
humanhash: paris-beryllium-hot-east
File name:R ALHTQ19-TYPBLDGP0401-940 GR2P5 -NASE FERDAN Q0539 NE-Q22.zip
Download: download sample
Signature AgentTesla
File size:104'435 bytes
First seen:2021-03-29 07:52:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:okUYZ0zb+6AFzFsMDh63RsUGcCdmZhAgVoa5pvLQrlkyCd2d0K4aaoeJJpR:okWnBIFs5RvmgVoaTe6yCdAHXcJT
TLSH 44A31240ED8D3A009D221A5EDD7643DD974AAEB3AF590C5F0D281023E945C2FBE368E8
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: se2p-iad1.servconfig.com
Sending IP: 199.250.216.161
From: Wasif Ahmed <amsadeghzadeh@ce.sharif.ir>
Subject: FW: RE: Samrudh Pharma - Tarapur JASCO HPLC - OUTSTANDING PAYMENT 3/29/2021 12:27:25 a.m.
Attachment: R ALHTQ19-TYPBLDGP0401-940 GR2P5 -NASE FERDAN Q0539 NE-Q22.zip (contains "R ALHTQ19-TYPBLDGP0401-940 GR2P5 -NASE FERDAN Q0539 NE-Q22.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2021-03-29 07:53:08 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5d9a4ea6dfc1910c1cdcd6d98c0a4c10a97c34f69f0f0ed7071376dd23ae4b41

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments