MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 7a5c5f30321386589942d761dd42e5dad80a9163720b346326b7f77d37225454. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 7a5c5f30321386589942d761dd42e5dad80a9163720b346326b7f77d37225454 |
|---|---|
| SHA3-384 hash: | caf1f7ff02b4d4b39abdf90c9cdae973de308014bced537f14ec2676f877fc2475ab13ca6a3da4939aef45187a3f7e48 |
| SHA1 hash: | d4dfe6b4d22c1adbceeb9f20c2dc66aaec2ace1d |
| MD5 hash: | f665a2ec02a7ffff9bffa7489b06b32b |
| humanhash: | queen-sodium-autumn-autumn |
| File name: | Payment Advice-BC_EDC9.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'245'184 bytes |
| First seen: | 2020-11-20 08:03:13 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 6144:JqRnIUaXdKT0882Q5Tp5HqMwR1ZBPmodPOVbQieEaAu6bEEAmg+S8:wxIL1882gTH+lB5dPO5QiFbIEAmDX |
| TLSH | 3A456CA0642BA865F52A0D37D6E9F66002737E0B9DC76D0870ADB71613F3352BE4684F |
| Reporter | |
| Tags: | AgentTesla img |
abuse_ch
Malspam distributing unidentified malware:HELO: mozzatbrunei.com
Sending IP: 45.133.203.90
From: Hr<hr@mozzatbrunei.com>
Subject: Check Payment Advice-BC_EDC95320201
Attachment: Payment Advice-BC_EDC9.img (contains "Payment Advice-BC_EDC9.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
132
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-20 08:04:06 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.