MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aac29372d431c82930481be3f51b9bcfffcd26892bcdc80d988d184c6199e9ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: aac29372d431c82930481be3f51b9bcfffcd26892bcdc80d988d184c6199e9ce
SHA3-384 hash: 3dcdf623df3fc232f3972e35eb54c3f8a82317364a4f6e3801c23d0df0b2f2c27a777c116ead386c13f01e498b8103f1
SHA1 hash: 143d92fdc6e63530794033408fdfc3eb35546c1c
MD5 hash: b67808e91b2ec1068d7f984d25268fce
humanhash: mississippi-edward-sad-north
File name:KN95 face mask list pdf.arj
Download: download sample
Signature AgentTesla
File size:473'412 bytes
First seen:2020-04-29 19:33:21 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:i2YSXyAZwSWXnZrv+7/jPffhhaKP/2uRflD47o2Y:OSXyEwRXo7/jPnbaKX2Wx4xY
TLSH DCA4235F0CD09B3BD4AF7604822F146B436B51DDF2E9A720CFEE8D8119A6371644C7A6
Reporter abuse_ch
Tags:AgentTesla arj COVID-19


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: renal-medical.com
Sending IP: 38.68.36.196
From: ventas@renal-medical.com
Subject: Provide disposable mask,forehead thermometer, KN95 face mask
Attachment: KN95 face mask list pdf.arj (contains "KN95 face mask list pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 19:36:04 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj aac29372d431c82930481be3f51b9bcfffcd26892bcdc80d988d184c6199e9ce

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments