MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c55a3cbb294ff5b2c616940adb5d32b8d278fd55769f13ca100d2eb7ecf6a96b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c55a3cbb294ff5b2c616940adb5d32b8d278fd55769f13ca100d2eb7ecf6a96b
SHA3-384 hash: 3b3d27572f3cdd12e8853d2a30288b65fe53805ac789e4bc2a5d0178a49175f4963a3eb7fad4778983192a3974b7cb71
SHA1 hash: 8b76cfacdabd7285c23bd9491385ccabe188359e
MD5 hash: 450fb178754c61131aebdacd82922cbc
humanhash: echo-fanta-delta-helium
File name:New Order #442-173.PDF.z
Download: download sample
Signature AgentTesla
File size:441'707 bytes
First seen:2020-09-16 18:38:47 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:d/3KZ6QnTYns5o5MpGzN0gy81breI4QxvfXt:V3W6QnZ5o5/ZycrHvdPt
TLSH 0B94237281F982F32C9B35F0434149C3BA5688D82E225BD1649A6DF5EE47AB5E2005BF
Reporter cocaman
Tags:AgentTesla z


Avatar
cocaman
Malicious email (T1566.001)
From: "NGUYEN THI <info@s-eikodo.vn>"
Received: "from s-eikodo.vn (unknown [103.153.182.164]) "
Date: "16 Sep 2020 08:47:52 -0700"
Subject: "NEW ORDER FOR SHIPMENT TO VIETNAM"
Attachment: "New Order #442-173.PDF.z"

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-09-16 16:06:35 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z c55a3cbb294ff5b2c616940adb5d32b8d278fd55769f13ca100d2eb7ecf6a96b

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments