MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 aa2e94e40f4e802e1344530cd8e3fbf0117496d91a6245e5d02d6e48642e9940. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | aa2e94e40f4e802e1344530cd8e3fbf0117496d91a6245e5d02d6e48642e9940 |
|---|---|
| SHA3-384 hash: | bdcc1eaf4b68415271680b9b3998af0cb7b0816977016c33d17cb00ac89b6e332e9dc782eb369791c4b175b4ffd12e47 |
| SHA1 hash: | 3105c5a4c48a5261f0603c512384da17c5f6a7dc |
| MD5 hash: | 510092689f6b74b61afa9c5e4c77532c |
| humanhash: | bulldog-east-west-fix |
| File name: | Hong Kong File.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 494'122 bytes |
| First seen: | 2020-10-05 05:24:42 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:6cg/iweJahdcgDfwJbZRzwZEXExCPGoUn2gNXlccssUAR77wLJTVFZOORehe:6JEgZUJF1wZerU2g+XARA9hFZ8e |
| TLSH | 31B42302B972D6E3FF53A17F718B5613627A66D431B7681A1A6C33FE8830532B277091 |
| Reporter | |
| Tags: | AgentTesla gz |
cocaman
Malicious email (T1566.001)From: "Slbraen <slbraen@braenstone.com>"
Received: "from bv-b3.yuvanetworks.in (unknown [103.108.48.250]) "
Date: "Sun, 04 Oct 2020 20:18:07 -0700"
Subject: "document of shipment from Hong Kong. co ltd"
Attachment: "Hong Kong File.gz"
Intelligence
File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Agensla
Status:
Malicious
First seen:
2020-10-05 03:12:55 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.