MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60a1b30396ff3462336e5cfa0e538dff7ec313fff46f28e3f4abd093346a7d69. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 60a1b30396ff3462336e5cfa0e538dff7ec313fff46f28e3f4abd093346a7d69
SHA3-384 hash: 09637d002c36aa70d927e24bbf936d633d5255aa080eb408ea65c52075c4959caac19c2f66e6b72d2872b6ec9022045d
SHA1 hash: 57bcba16482be2b48ea843a84d1136659e8bde98
MD5 hash: 4dbcd7bdd55f07d64a2350fd88db4cbb
humanhash: foxtrot-steak-alabama-green
File name:Invoice55565.zip
Download: download sample
Signature AgentTesla
File size:613'242 bytes
First seen:2021-04-01 18:37:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:MrX9WcsD86eLWR1eqG29APwtKu6ATefXRvFtqb4IOn5jdQYoE+tqcYC/lRU:MjHsDDpRgy9APDuKf9ybZO5RTCqaY
TLSH C2D423E7856CFF42300B25D06D6DC6534A20813DBFB8E2D4B2B54119728A397E2B9DF9
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: hosted-4-client-dedicated-live-server.kinsliemail.com
Sending IP: 103.102.239.91
From: Gualaine Exports L.L.C <mailserver565@administrator.com>
Subject: Re: Fwd: Bank Transfer
Attachment: Invoice55565.zip (contains "Invoice55565.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-04-01 18:38:13 UTC
AV detection:
12 of 46 (26.09%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 60a1b30396ff3462336e5cfa0e538dff7ec313fff46f28e3f4abd093346a7d69

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments