MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea6d13ca023163634bef23132b5629deff4e7d9dc1d323d44808641fa98d2827. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea6d13ca023163634bef23132b5629deff4e7d9dc1d323d44808641fa98d2827
SHA3-384 hash: 1a6f822e685898026f2c9c4291b95b378baf2235bdeb377fdd5f8d8a40f42c05e6e0a498e277ec1ff4fa012288971fdf
SHA1 hash: 83fbe247e994a9f21206b0c9f8a364bdcb39bf18
MD5 hash: dab44ee14d04984675bb5604f4de0579
humanhash: july-california-purple-bacon
File name:NEW ORDER INQUIRY _B1020363.pdf.gz
Download: download sample
Signature AgentTesla
File size:551'144 bytes
First seen:2020-09-01 11:10:43 UTC
Last seen:2020-09-01 15:02:40 UTC
File type: gz
MIME type:application/x-rar
ssdeep 12288:QDVaJSePdP2WoyrGlfwdgGdTGwhTm0HRSQ+tchQd3kyYc2tAu7Z:QDaBPB2WByKdVT5Acpho3kyYb37Z
TLSH C1C423C8AC720E4BDD240F88EEA6CB0A651D3A94C014F787B6D09EDFA1645D63725B4A
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: Jiangchuan Junguan <sales@zorrotz.com>
Received: from zorrotz.com (unknown [45.137.22.76])
Date: 1 Sep 2020 08:01:40 -0700
Subject: NEW ORDER INQUIRY _B1020363
Attachment: NEW ORDER INQUIRY _B1020363.pdf.gz

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-09-01 11:04:05 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz ea6d13ca023163634bef23132b5629deff4e7d9dc1d323d44808641fa98d2827

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments