MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ac4358913546d185a5b011a16926276f9dbf1375a67802c186fd137f187c1dac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | ac4358913546d185a5b011a16926276f9dbf1375a67802c186fd137f187c1dac |
|---|---|
| SHA3-384 hash: | 1d6a49a312ada67ffcdeb000e477aa30fa129633a66010d685a6749e78134d88b5a4dd2345c7043846b59fcc16d6a38e |
| SHA1 hash: | e324f440f9b9b6e06b891fd4c6afc65ee0ef33e2 |
| MD5 hash: | 81a43ff1f72e136b33934869cdbf512f |
| humanhash: | alabama-ohio-happy-seven |
| File name: | Revised Proforma Invoice_New order.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 318'698 bytes |
| First seen: | 2021-09-28 06:08:15 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 6144:vPtecom55GAwqZg7R7enleXftarS+Z5OBTVJKAK0O0:34coiReFenleXfBO0 |
| TLSH | T1A2642301F66DBB0FAB92C792B9035C4C526C02FAB984CFCB69F63158C6198365DF3616 |
| Reporter | |
| Tags: | AgentTesla INVOICE z |
cocaman
Malicious email (T1566.001)From: ""Milan Hertman" <bon@meise.co.jp>" (likely spoofed)
Received: "from meise.co.jp (unknown [45.137.22.101]) "
Date: "27 Sep 2021 23:02:53 +0200"
Subject: "Revised Proforma Invoice_New order Al Saad Trading (TOP URGENT)"
Attachment: "Revised Proforma Invoice_New order.z"
Intelligence
File Origin
# of uploads :
1
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-09-27 19:24:39 UTC
AV detection:
14 of 45 (31.11%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.