MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85b0956a724dd062a264dba26514ff9f3504adf18a8e66fb87d21ea0198ef229. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 85b0956a724dd062a264dba26514ff9f3504adf18a8e66fb87d21ea0198ef229
SHA3-384 hash: e670965e98ab8ad3056f9ac3ad0d3ce7dc3c1ea5f9496e9c6dcf28466a3eab70518c15cab3e0a02a45512b9bf935f5cc
SHA1 hash: 78615cb98bd51e94b8be79f97d3b1463f1e446bc
MD5 hash: 6985935030922d8a69a37b22ace2c959
humanhash: five-pennsylvania-white-oregon
File name:PO 05090920.zip
Download: download sample
Signature AgentTesla
File size:426'918 bytes
First seen:2020-08-11 10:51:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:gXWcMCso3Od41SOBUM9GeK2vR7TIac4tHC/BRwTZoGEUXHBs0lIWLnyydXU1O:gmcM7o3+yFSW7Ej4JK4TZzEYs0lqgXd
TLSH 7494236248BE8667BB09F112ED0ECDC5AA1746994D0F0664D0C827CD36C6F9EC2787F5
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fujifilm.com.pk
Sending IP: 95.211.253.211
From: Wanna Colin Yuan <fuji.sahiwal@fujifilm.com.pk>
Subject: RE: PURCHASE ORDER
Attachment: PO 05090920.zip (contains "PO 05090920.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-11 10:53:05 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 85b0956a724dd062a264dba26514ff9f3504adf18a8e66fb87d21ea0198ef229

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments