MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5dc555294277e9a675780bb9825a692df4c2c3569523d0337f6e7bd0fdc55eed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 5dc555294277e9a675780bb9825a692df4c2c3569523d0337f6e7bd0fdc55eed |
|---|---|
| SHA3-384 hash: | 2e3a0ab82a3565f3c0ef21a9fb958bb1247f258ab7eb0278cbec887aabfd13ef366dbb462901e983b553fc5ec4a81b0a |
| SHA1 hash: | 258962843ab77be940c909bc2e9754a87a412868 |
| MD5 hash: | fdaa2104cc7d8545e4a69bd4e2ad317d |
| humanhash: | north-cat-winner-delaware |
| File name: | PURCHASE ORDER.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 479'918 bytes |
| First seen: | 2021-01-06 07:44:39 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:ebGBx4JKO2PbklJD15gT3dhDtyacbChKz6BuxWrW4+1JPxvXK+r5oOVl0UpkvxkD:7BzkXD1I1c2kzAcWStPj5oOyxkD |
| TLSH | 9DA4231396E426A65ED6CA2E2F9EE6886EC4301139988780F1C74C3981372DFF7855FC |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: gmail.com
Sending IP: 185.222.57.135
From: Zubair Razavi <zubairridawi@gmail.com>
Subject: RE:PURCHASE ORDER
Attachment: PURCHASE ORDER.rar (contains "PURCHASE ORDER.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
168
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Backdoor.Crysan
Status:
Malicious
First seen:
2021-01-06 07:45:05 UTC
AV detection:
15 of 46 (32.61%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.