MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fca24a9578f4321cc8068bda045eaa4832b31cb63ea9b0953b6cac2cef5a43d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: 8fca24a9578f4321cc8068bda045eaa4832b31cb63ea9b0953b6cac2cef5a43d
SHA3-384 hash: af4244d6b761cfa959c25347717018b3098baa18a4fa7994f89ea76b882e593f73e3670d95a5643029949c3d83b50fcd
SHA1 hash: a01e6a32b64cf51682555c58ac13ad5e78c8dcce
MD5 hash: 764dca0446ffe5a4bd6f25bc4acad474
humanhash: king-delta-floor-freddie
File name:PURCHASE ORDER.rar
Download: download sample
Signature AgentTesla
File size:967'051 bytes
First seen:2020-05-22 04:49:39 UTC
Last seen:2020-05-25 08:36:42 UTC
File type: rar
MIME type:application/x-rar
ssdeep 24576:HCuoFXUai40jg18fOSAKTAAcUQ6dtN0HgLfTdZGPfFh9U:HCuO/sg1T4kFULnqHgLf+jy
TLSH 592533EC409B28828C5469B7C6CD17B4879D0325D8FECFD25AE857A5A5F8BCF412E0B4
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
3
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-22 07:44:35 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
14 of 30 (46.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8fca24a9578f4321cc8068bda045eaa4832b31cb63ea9b0953b6cac2cef5a43d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
Corsin Camichel commented on 2020-05-25 08:38:47 UTC

Malicious email
From: "J.MURALI" <sales271@blowpack.in>
Received: from blowpack.in (unknown [45.137.22.85])
Date: 21 May 2020 23:43:54 -0700
Subject: FWD: PURCHASE ORDER
Attachment: PURCHASE ORDER.rar