MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa2e94e40f4e802e1344530cd8e3fbf0117496d91a6245e5d02d6e48642e9940. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: aa2e94e40f4e802e1344530cd8e3fbf0117496d91a6245e5d02d6e48642e9940
SHA3-384 hash: bdcc1eaf4b68415271680b9b3998af0cb7b0816977016c33d17cb00ac89b6e332e9dc782eb369791c4b175b4ffd12e47
SHA1 hash: 3105c5a4c48a5261f0603c512384da17c5f6a7dc
MD5 hash: 510092689f6b74b61afa9c5e4c77532c
humanhash: bulldog-east-west-fix
File name:Hong Kong File.gz
Download: download sample
Signature AgentTesla
File size:494'122 bytes
First seen:2020-10-05 05:24:42 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:6cg/iweJahdcgDfwJbZRzwZEXExCPGoUn2gNXlccssUAR77wLJTVFZOORehe:6JEgZUJF1wZerU2g+XARA9hFZ8e
TLSH 31B42302B972D6E3FF53A17F718B5613627A66D431B7681A1A6C33FE8830532B277091
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email (T1566.001)
From: "Slbraen <slbraen@braenstone.com>"
Received: "from bv-b3.yuvanetworks.in (unknown [103.108.48.250]) "
Date: "Sun, 04 Oct 2020 20:18:07 -0700"
Subject: "document of shipment from Hong Kong. co ltd"
Attachment: "Hong Kong File.gz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Agensla
Status:
Malicious
First seen:
2020-10-05 03:12:55 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz aa2e94e40f4e802e1344530cd8e3fbf0117496d91a6245e5d02d6e48642e9940

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments