MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 85b0956a724dd062a264dba26514ff9f3504adf18a8e66fb87d21ea0198ef229. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 85b0956a724dd062a264dba26514ff9f3504adf18a8e66fb87d21ea0198ef229 |
|---|---|
| SHA3-384 hash: | e670965e98ab8ad3056f9ac3ad0d3ce7dc3c1ea5f9496e9c6dcf28466a3eab70518c15cab3e0a02a45512b9bf935f5cc |
| SHA1 hash: | 78615cb98bd51e94b8be79f97d3b1463f1e446bc |
| MD5 hash: | 6985935030922d8a69a37b22ace2c959 |
| humanhash: | five-pennsylvania-white-oregon |
| File name: | PO 05090920.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 426'918 bytes |
| First seen: | 2020-08-11 10:51:28 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:gXWcMCso3Od41SOBUM9GeK2vR7TIac4tHC/BRwTZoGEUXHBs0lIWLnyydXU1O:gmcM7o3+yFSW7Ej4JK4TZzEYs0lqgXd |
| TLSH | 7494236248BE8667BB09F112ED0ECDC5AA1746994D0F0664D0C827CD36C6F9EC2787F5 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: fujifilm.com.pk
Sending IP: 95.211.253.211
From: Wanna Colin Yuan <fuji.sahiwal@fujifilm.com.pk>
Subject: RE: PURCHASE ORDER
Attachment: PO 05090920.zip (contains "PO 05090920.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-11 10:53:05 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.