MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a315b1a9375412563abc3d4c3049de10935d280853edced22b1570acba0b8d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9a315b1a9375412563abc3d4c3049de10935d280853edced22b1570acba0b8d8
SHA3-384 hash: c13876a938da4e3a7b5757c9b72b578ce48533defbc2340d728579c1759ceea1419cb1dfea650c24c1c26f5fcb13a177
SHA1 hash: b32919e394dab197862b810c65ffe46ce940bae0
MD5 hash: 1c43c9c8357888cfcd367117c91b6a89
humanhash: item-indigo-two-sierra
File name:Halkbank_Ekstre_20201104_080254_102872.pdf.r00
Download: download sample
Signature AgentTesla
File size:576'208 bytes
First seen:2020-11-05 00:25:27 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:UQJCImpccYd2V/AFI2rYgRHIXvYC78kunOVuZe5qd9bws8:lJPmpNaIA2/gR2Ae5k90v
TLSH 87C4238DF4DEF0CC91C9A026B1B91152CEB4F6356C45598BA82E39E9C00B0EB6D5BD7C
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-05 00:27:03 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 9a315b1a9375412563abc3d4c3049de10935d280853edced22b1570acba0b8d8

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments