MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac61d85cc1996bf13fdbd05f59709633ae347496d128e301adc42cb315c2a07a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ac61d85cc1996bf13fdbd05f59709633ae347496d128e301adc42cb315c2a07a
SHA3-384 hash: f35ca96fa13704725f093de62b86b25f90ed1411e8de9d23a5534e2ed0e14954a0c2697a208d0da6e9ac171a10f7702e
SHA1 hash: 41448b8cd7ad3ac5b39ebd8a88cb5ed56cb88528
MD5 hash: e6a0fb946f1df38f7e26d8010e953ab8
humanhash: minnesota-uniform-india-xray
File name:estatement_01_03_2021.7z
Download: download sample
Signature AgentTesla
File size:1'531'460 bytes
First seen:2021-01-04 07:36:05 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 24576:Dlw+A6em+gCVHbYvfK/9oA9jHzKYYx/XVjcMHK5SzqFxtIQPNyCQVYClbVyTsf1W:hmDgChY3S9RdHzdYhXFcMmSubI6NyCQa
TLSH 8E653327A36A23845DBDE1E94A160934336BC2921FB01965D16CFFF517B033AF32D692
Reporter abuse_ch
Tags:7z HostGator


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gateway34.websitewelcome.com
Sending IP: 192.185.148.231
From: estatement@rakbank.ae <transport@ozkahil.com>
Subject: RAKBANK Business Account e-Statement
Attachment: estatement_01_03_2021.7z (contains "estatement_01_03_2021.bat")

Intelligence


File Origin
# of uploads :
1
# of downloads :
224
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z ac61d85cc1996bf13fdbd05f59709633ae347496d128e301adc42cb315c2a07a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments