MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d287c493020eda6dc7abdef0e22272e71e3fbc1b4f6cdb8e15e4ad7a56e4b0be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d287c493020eda6dc7abdef0e22272e71e3fbc1b4f6cdb8e15e4ad7a56e4b0be
SHA3-384 hash: af618193981bfab2aae09463627a1e1a5b042e2e345bb2c18bb12246b2d43b6a431f62b5a29eca0aa9447903cbadca95
SHA1 hash: 706ce045bc65068600d4516f69bf336e65a9089c
MD5 hash: 5bd4e107dda351957879c63ecabd223a
humanhash: river-blossom-virginia-nevada
File name:pdf.rar
Download: download sample
Signature AgentTesla
File size:465'458 bytes
First seen:2020-10-23 07:02:44 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:30cJ0GpGdrykEJVYe9KgUmBTySKURc+EiLkof+Q:39aGpEEJ3wgUUnRSiLkof+Q
TLSH 25A423390C3ABD4FDC2AF0C4209BD5F08A297FE8295DA4F76217D6D565209387A8371B
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: cpns2.citechco.net
Sending IP: 203.191.33.181
From: moslem@formosatex.com
Subject: Re: Final Proforma Invoice
Attachment: pdf.rar (contains "pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-22 22:28:55 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d287c493020eda6dc7abdef0e22272e71e3fbc1b4f6cdb8e15e4ad7a56e4b0be

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments