MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac4358913546d185a5b011a16926276f9dbf1375a67802c186fd137f187c1dac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ac4358913546d185a5b011a16926276f9dbf1375a67802c186fd137f187c1dac
SHA3-384 hash: 1d6a49a312ada67ffcdeb000e477aa30fa129633a66010d685a6749e78134d88b5a4dd2345c7043846b59fcc16d6a38e
SHA1 hash: e324f440f9b9b6e06b891fd4c6afc65ee0ef33e2
MD5 hash: 81a43ff1f72e136b33934869cdbf512f
humanhash: alabama-ohio-happy-seven
File name:Revised Proforma Invoice_New order.z
Download: download sample
Signature AgentTesla
File size:318'698 bytes
First seen:2021-09-28 06:08:15 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:vPtecom55GAwqZg7R7enleXftarS+Z5OBTVJKAK0O0:34coiReFenleXfBO0
TLSH T1A2642301F66DBB0FAB92C792B9035C4C526C02FAB984CFCB69F63158C6198365DF3616
Reporter cocaman
Tags:AgentTesla INVOICE z


Avatar
cocaman
Malicious email (T1566.001)
From: ""Milan Hertman" <bon@meise.co.jp>" (likely spoofed)
Received: "from meise.co.jp (unknown [45.137.22.101]) "
Date: "27 Sep 2021 23:02:53 +0200"
Subject: "Revised Proforma Invoice_New order Al Saad Trading (TOP URGENT)"
Attachment: "Revised Proforma Invoice_New order.z"

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-09-27 19:24:39 UTC
AV detection:
14 of 45 (31.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z ac4358913546d185a5b011a16926276f9dbf1375a67802c186fd137f187c1dac

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments