MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60da15fcff09ae3f50f8f94b8635fc00e4cfe50cfb5b8af15b508bdd1941db19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 60da15fcff09ae3f50f8f94b8635fc00e4cfe50cfb5b8af15b508bdd1941db19
SHA3-384 hash: 24965a859aac770f96e71f0f7a3abd467c84e759083a86cbacd9ebef2c617bbaee8d567ae05d8aa5aeb9e32d51e8feca
SHA1 hash: bd72f1a5723044974cf0387923185e94b012ddd5
MD5 hash: 848287e6a195865a09f8ed551c989bf8
humanhash: don-golf-bluebird-sink
File name:MT XIN SHEN YANGV66.cab
Download: download sample
Signature AgentTesla
File size:565'060 bytes
First seen:2021-03-03 07:31:58 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:cRPxfDbyZpFYFk+yUfOt1nOUlyHsjxI0DmFgPeoQflJJt7dm:cRJ3zyUfOrOmmyPeoQflJJtJm
TLSH 83C433202DDF23725C03F6758647FCF3C26B2F1415D2D52D6AB9A82A628D22FDD86D90
Reporter abuse_ch
Tags:cab


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: "parkjh/JiHyun Park(COSCOKOREA SEOUL)" <park.jh@coscokorea.com>
Subject: MT XIN SHEN YANG(V66)/AGENCY APPOINTMENT
Attachment: MT XIN SHEN YANGV66.cab (contains "MT XIN SHEN YANG(V66).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-03-03 04:38:29 UTC
AV detection:
8 of 47 (17.02%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 60da15fcff09ae3f50f8f94b8635fc00e4cfe50cfb5b8af15b508bdd1941db19

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments