MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e1f09f50a794fd933b208be4a409e5149fd03ba8dc3516ed804348e5baf482c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 8
| SHA256 hash: | e1f09f50a794fd933b208be4a409e5149fd03ba8dc3516ed804348e5baf482c2 |
|---|---|
| SHA3-384 hash: | 92b468ea29319eb39d83c8bb24baabcf2b62c775b8eb865f280c5cdca9eea513027f84d063b6b6d0a86c39df61560b3d |
| SHA1 hash: | 503ea7c6f22f014c9aa0ea79df04172fc3c217b1 |
| MD5 hash: | 2ca3f9c8fb1c767d3a066e3deea29029 |
| humanhash: | march-cola-solar-hydrogen |
| File name: | PO INS 0124.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 697'659 bytes |
| First seen: | 2023-12-19 08:49:15 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:m8sYPSHPmFEnYLaBC7cN46FT/cZXaZwENPFmoI1mVBSAyPTZ:mYaHP6EnrBC7cNXZUUbNNmo2mzS5Z |
| TLSH | T1C9E4232063BFAE862631C41450F9EA04D4FC456F95D4231FF67FA913E9A3F902806E79 |
| TrID | 80.0% (.ZIP) ZIP compressed archive (4000/1) 20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1) |
| Reporter | |
| Tags: | AgentTesla zip |
cocaman
Malicious email (T1566.001)From: ""Sealock Jane" sealock8@sealock.com.hk" (likely spoofed)
Received: "from hosted-by.rootlayer.net (unknown [45.137.22.165]) "
Date: "18 Dec 2023 22:10:07 +0100"
Subject: "NEW PURCHASE ORDER PO INS 0124"
Attachment: "PO INS 0124.zip"
Intelligence
File Origin
CHFile Archive Information
This file archive contains 1 file(s), sorted by their relevance:
| File name: | PO INS 0124.exe |
|---|---|
| File size: | 936'960 bytes |
| SHA256 hash: | 0eed254ba5c7e7cc2b6ac08be4b1a450d453b58ed58d5b23caed7fb0db89961a |
| MD5 hash: | 76253e7ea3523aa5468177784587ee07 |
| MIME type: | application/x-dosexec |
| Signature | AgentTesla |
Vendor Threat Intelligence
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
AgentTesla
zip e1f09f50a794fd933b208be4a409e5149fd03ba8dc3516ed804348e5baf482c2
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.