MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc5e8cc75e22f7bfaa6c32131b484febe6e10f7164e8d411e046d76f06f1e49a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc5e8cc75e22f7bfaa6c32131b484febe6e10f7164e8d411e046d76f06f1e49a
SHA3-384 hash: 15aea597c12917bb81553a7e57665ba02328c30f781bf6213187456d761f01ea45b26d4ffeb8429d9581c32bdf9006fe
SHA1 hash: 2efd7aa1d0b7382df948a1c978f3934864767349
MD5 hash: 4427b61ee2c08d1b3f18e4ec57ed5ebd
humanhash: yellow-bacon-december-nebraska
File name:specification and drawing.r00
Download: download sample
Signature AgentTesla
File size:15'401 bytes
First seen:2020-12-17 08:37:30 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 384:wKPPR+n+miwTlMM1R1MjwUDeRdl1OmX4bSZ:b+nj7T6mmhaNISZ
TLSH 6E62D0CD42D35379FB150BA1FCB7582B2E0118DE5D9893BC91B8D45C0EE762A6213CDA
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: correo.trcnet.com.ar
Sending IP: 190.227.12.3
From: Ege Termo Elek. İnfo <vera@credifinexpress.com.ar>
Subject: Updated PO
Attachment: specification and drawing.r00 (contains "specification and drawing.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Downloader.Generic
Status:
Suspicious
First seen:
2020-12-17 08:38:05 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 dc5e8cc75e22f7bfaa6c32131b484febe6e10f7164e8d411e046d76f06f1e49a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments