MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 85543c20080298ed64f4c97ed677d268eb2a3527ade73a22ef344a64d183568a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 85543c20080298ed64f4c97ed677d268eb2a3527ade73a22ef344a64d183568a |
|---|---|
| SHA3-384 hash: | f1948229a6729aeb9fb5e86ca4351f438836530e52412ef23356972a036b91d584bd468868efe56496735f4c957d5a0f |
| SHA1 hash: | d81307f4d032f81a4cd744587b5d8da92384b8d5 |
| MD5 hash: | d0fd9fd405a7b1d58e53cdc0750dfa07 |
| humanhash: | potato-eighteen-maine-lithium |
| File name: | Shipping Document PLBL Draft.r00 |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 375'344 bytes |
| First seen: | 2020-10-20 07:22:36 UTC |
| Last seen: | Never |
| File type: | r00 |
| MIME type: | application/x-rar |
| ssdeep | 6144:8hJBEpx9oKZnz0A09OmbGvu7Gif3PcH1ygahGw8B+JQSpGWJ/cmUGtzXDndwM4vy:O6pjZnwQm+OQLahGK5Z/clGtTD6M4agI |
| TLSH | 2D842334CDEDE4D5D8BE60B68132C5A16C95883DB6D056B3EC5E94CDF2A320AD08FE61 |
| Reporter | |
| Tags: | AgentTesla r00 TNT |
abuse_ch
Malspam distributing AgentTesla:HELO: dbd0.303.mevvia.ml
Sending IP: 178.62.94.127
From: TNT EXPRESS <john@bcmcorporate.com>
Subject: Consignment Notification: You Have A Package With Us
Attachment: Shipping Document PLBL Draft.r00 (contains "Shipping Document PL&BL Draft.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Ransomware.Generic
Status:
Suspicious
First seen:
2020-10-19 23:03:17 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.