MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d71887fd5dbef4c1eaa0462c508d9415722dbdb92f4b835edbae7249acc36fdb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
BitRAT
Vendor detections: 5
| SHA256 hash: | d71887fd5dbef4c1eaa0462c508d9415722dbdb92f4b835edbae7249acc36fdb |
|---|---|
| SHA3-384 hash: | 813a674830519fad71e791b2294a64c8e8537900aa2fae7ff08222d46dd37639efbb09c1194de15990ae55d8abbfb01b |
| SHA1 hash: | e265e0e50537e9439d88c07012a3da448fb9c5b0 |
| MD5 hash: | d7b34cfb757e6dd1d4f7c9993775ce7c |
| humanhash: | india-london-twelve-muppet |
| File name: | Xerox02-02-2021.Pdf.jpg.img |
| Download: | download sample |
| Signature | BitRAT |
| File size: | 1'245'184 bytes |
| First seen: | 2021-02-02 09:43:28 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 3072:CiXNVAkvnW/ZxsoYnb9mXCJgJFREE7eARvlid0PpQLXD:CiXNVACnuxsoib9mXCJa8LX |
| TLSH | BE45C58192084A51F679A731B23251237BB11CD6BDF74E1DB8DD368336F26832E9294F |
| Reporter | |
| Tags: | BitRAT img RAT |
abuse_ch
Malspam distributing BitRAT:HELO: rdns0.private-online-ehnational.com
Sending IP: 139.28.36.119
From: Sukru Yildiz <vinipihsa@gmail.com>
Subject: PROFORMA
Attachment: Xerox02-02-2021.Pdf.jpg.img (contains "Xerox02-02-2021.scr")
BitRAT C2:
jegebit.duckdns.org
Intelligence
File Origin
# of uploads :
1
# of downloads :
130
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-02 09:44:14 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.51
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
BitRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.