MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60ebf72039b411a6b672b15e842c6cefb1e270cb856a7d86c8155d02fd29900a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 60ebf72039b411a6b672b15e842c6cefb1e270cb856a7d86c8155d02fd29900a
SHA3-384 hash: 2be6f54820cea3a9e455001c490a8d366c4c216c9c292f852fc4809870a73bd1febe922cbc0fe79766285d2c70f71fc7
SHA1 hash: e1036a4270bd4b4e83832acb81ce61c3a8b33519
MD5 hash: 43aa62a1f9229499cfb922467b003d35
humanhash: iowa-ack-yankee-social
File name:BANK PAYMENT______pdf_____________________________.zip
Download: download sample
Signature AgentTesla
File size:723'880 bytes
First seen:2021-04-07 13:42:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:XpXvp/iMIzTFknDTSNIKGJ2TGTLF/xU9SMC+R4S1RT7xpem40A10:5/p/AFlXGJ2TopU9ES1Ne0Aa
TLSH AEF423FF0B76F1FE109BD7F1A22D74916748E6353C18C82DF1965E16260767282A2CA3
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-04-07 10:47:42 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 60ebf72039b411a6b672b15e842c6cefb1e270cb856a7d86c8155d02fd29900a

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments