MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a5c5f30321386589942d761dd42e5dad80a9163720b346326b7f77d37225454. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7a5c5f30321386589942d761dd42e5dad80a9163720b346326b7f77d37225454
SHA3-384 hash: caf1f7ff02b4d4b39abdf90c9cdae973de308014bced537f14ec2676f877fc2475ab13ca6a3da4939aef45187a3f7e48
SHA1 hash: d4dfe6b4d22c1adbceeb9f20c2dc66aaec2ace1d
MD5 hash: f665a2ec02a7ffff9bffa7489b06b32b
humanhash: queen-sodium-autumn-autumn
File name:Payment Advice-BC_EDC9.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-11-20 08:03:13 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:JqRnIUaXdKT0882Q5Tp5HqMwR1ZBPmodPOVbQieEaAu6bEEAmg+S8:wxIL1882gTH+lB5dPO5QiFbIEAmDX
TLSH 3A456CA0642BA865F52A0D37D6E9F66002737E0B9DC76D0870ADB71613F3352BE4684F
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mozzatbrunei.com
Sending IP: 45.133.203.90
From: Hr<hr@mozzatbrunei.com>
Subject: Check Payment Advice-BC_EDC95320201
Attachment: Payment Advice-BC_EDC9.img (contains "Payment Advice-BC_EDC9.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-20 08:04:06 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 7a5c5f30321386589942d761dd42e5dad80a9163720b346326b7f77d37225454

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments