🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d72d67034b170fb2bfdffe970d9340ab5189b5fd51ae01c3b3f014c4f775cabc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d72d67034b170fb2bfdffe970d9340ab5189b5fd51ae01c3b3f014c4f775cabc
SHA3-384 hash: fde5caa2cc7d78634cc49de7da9aba8523c6c2f9d756f444c1e474d6033947e62c1ae1cbe37e555ec193eb8f46ff68a1
SHA1 hash: e1f4a656e643f0e42ad3f2ce49f350db17e93f19
MD5 hash: b9ce71bd22caf8c9a09bafa5c1d969f4
humanhash: magazine-london-pasta-island
File name:HYDRANTS & HOSE BOXES.pdf
Download: download sample
Signature AgentTesla
File size:395'835 bytes
First seen:2020-07-01 15:14:14 UTC
Last seen:2020-07-02 05:01:46 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:IiNs5tufKpA7sQsEJGm2C7t52g5ylUmkCqck:dNs5EfyARJp2C7UpKck
TLSH 1484231803F161594A97B8E8285F2FB6EC4C1CC1FCC8E82AD55F06497175F57C4AB8AE
Reporter cocaman
Tags:AgentTesla pdf


Avatar
cocaman
Malicious email
From: Abdo Hussein Ahmed<hndc_pro@petrojet.com.eg>
Received: from petrojet.com.eg (unknown [95.211.208.23])
Date: 1 Jul 2020 15:10:22 -0700
Subject: Fw: invitation for tender no. 264/HND/2020 to supply FIRE WATER HYDRANTS & HOSE BOXES
Attachment: HYDRANTS & HOSE BOXES.pdf

Intelligence


File Origin
# of uploads :
2
# of downloads :
154
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-07-01 15:16:05 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d72d67034b170fb2bfdffe970d9340ab5189b5fd51ae01c3b3f014c4f775cabc

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments