MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 dae1288abd29a401e732eb5bc1a2ff162fcdebe6525ec15309a5b5676debd98b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 7
| SHA256 hash: | dae1288abd29a401e732eb5bc1a2ff162fcdebe6525ec15309a5b5676debd98b |
|---|---|
| SHA3-384 hash: | da8f1d7947f2c79a86823030330eb63272895592e6aef71fb3612db52274aa184b713ac427cf7628b6ba898ba45ea1e9 |
| SHA1 hash: | c76b868e669da9cfa2e068620f927aa59e766fcb |
| MD5 hash: | b51386410a341b246f63332f151ed46a |
| humanhash: | oscar-violet-kilo-oxygen |
| File name: | ID-Statement of Account_s-XXXXX6290-081220232003311731.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 697'745 bytes |
| First seen: | 2023-12-19 08:48:48 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:G8sYPSHPmFEnYLaBC7cN46FT/cZXaZwENPFmoI1mVBSAyPT6:GYaHP6EnrBC7cNXZUUbNNmo2mzS56 |
| TLSH | T143E4232063BFEE862631C41050F9EA04D4FC456F95D4231FF67FA913E9A3E902916E79 |
| TrID | 80.0% (.ZIP) ZIP compressed archive (4000/1) 20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1) |
| Reporter | |
| Tags: | AgentTesla zip |
cocaman
Malicious email (T1566.001)From: ""FedEx Express - Do Not Reply" <RO-NOREPLY@fedex.com" (likely spoofed)
Received: "from hosted-by.rootlayer.net (unknown [45.137.22.165]) "
Date: "18 Dec 2023 22:09:57 +0100"
Subject: "None"
Attachment: "ID-Statement of Account_s-XXXXX6290-081220232003311731.zip"
Intelligence
File Origin
CHFile Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | ID-Statement of Account_s-XXXXX6290-081220232003311731.exe |
|---|---|
| File size: | 936'960 bytes |
| SHA256 hash: | 0eed254ba5c7e7cc2b6ac08be4b1a450d453b58ed58d5b23caed7fb0db89961a |
| MD5 hash: | 76253e7ea3523aa5468177784587ee07 |
| MIME type: | application/x-dosexec |
| Signature | AgentTesla |
Vendor Threat Intelligence
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
AgentTesla
zip dae1288abd29a401e732eb5bc1a2ff162fcdebe6525ec15309a5b5676debd98b
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.