MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c863f9552782e6bc04940127a31550a4632efa1f5cce23b61e4b65d9d0e6b35a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c863f9552782e6bc04940127a31550a4632efa1f5cce23b61e4b65d9d0e6b35a
SHA3-384 hash: 64be6c91b17fc85d72722ee3eb51eb1585502f0718f7365a6817b6797b22ea0a83cb1e27cffdde72e13ac69dfd330ca2
SHA1 hash: f40826a295aa76ae86442f20e1d8e323bed821a1
MD5 hash: 6947721d5f616f2a0facb1a23ecc67aa
humanhash: wisconsin-white-pip-early
File name:official PO PDF.img
Download: download sample
Signature AgentTesla
File size:124'928 bytes
First seen:2020-10-13 14:33:05 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 384:QsbuwHTbC0n2eHe8k61uTlI8ySar/L8R2/FmK9s2F6zvss4Y7ejg4sAclwYQJntR:Qguaxlk6zJ/YmFmkE4sAciloUf2h
TLSH 52C3D4443D46C59BC925983599B2EDA40AA2ED73D022E3B2AD9FF8D8F37D704FA43510
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: vps-e62a430c.vps.ovh.ca
Sending IP: 139.99.133.125
From: IFB Shenzhen Oprs - Rena Rong <mumdoc@mastergroups.com>
Subject: Agro Mega Trading Co.,Ltd PO
Attachment: official PO PDF.img (contains "official PO PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-13 10:11:46 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img c863f9552782e6bc04940127a31550a4632efa1f5cce23b61e4b65d9d0e6b35a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments