MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a05ec95cd73456e58e6ac83f442f0b65b6d27b36fb38420c1829f73696e8e6a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a05ec95cd73456e58e6ac83f442f0b65b6d27b36fb38420c1829f73696e8e6a4
SHA3-384 hash: e7df1217a75dc78f101a38af31bd6a3a968d4a3d49081a614cc8b0d2de805559a448a7aa4fd3c99b0c04db1a9e2ab4ad
SHA1 hash: 0bb66080dc9f31425ace8d719560f1f4fa8797f3
MD5 hash: 3f3fe5bd9037d4b8acecb103f5b05c82
humanhash: eight-black-one-social
File name:Richiesta Urgente.pdf.zip
Download: download sample
Signature AgentTesla
File size:438'154 bytes
First seen:2020-11-18 12:55:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:XXxNjF7EtUB99aGSlqjN936ha9JmABI8V5YV/n7JE1KYJEteEuBEmg:zFYtUL9axY93wkJmCHYJn7i1DNEv
TLSH E1942377E2BF3F8B69AB7A2CD40C4725B27CC47435E90DD21A208505166F1CE60B9E6D
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: normansrl.com
Sending IP: 185.239.242.114
From: elvira.vairo@normansrl.com
Subject: Richiesta Urgente
Attachment: Richiesta Urgente.pdf.zip (contains "Richiesta Urgente.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Spyware.Negasteal
Status:
Malicious
First seen:
2020-11-18 09:34:41 UTC
AV detection:
24 of 28 (85.71%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a05ec95cd73456e58e6ac83f442f0b65b6d27b36fb38420c1829f73696e8e6a4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments