MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efdd71930b1035b643332384adf41e59f6ca280bd9b4a922bad7776d0410ab51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: efdd71930b1035b643332384adf41e59f6ca280bd9b4a922bad7776d0410ab51
SHA3-384 hash: 34ed684b5074a4eef5373ff490a630f64dd4703a97c1356750686a28abf2085b3548934c200946db5d5e7dbbc9faee8b
SHA1 hash: dc9a6d6ac7c7ece633ecc206c2117477be266bba
MD5 hash: 0d857a4d436fbe928d6fe4435d8fbcf6
humanhash: fix-sixteen-wolfram-network
File name:drawings and specification contract.r00
Download: download sample
Signature AgentTesla
File size:613'262 bytes
First seen:2020-08-17 13:54:03 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:eJNasTF+6HbYsYXfvZve5vP+iToBq9fED1p+ZTshnyikCIwr4ampGEu2kkSSMwZq:etF+67Y7XflMQmOs7Mnr4pGEuxs/GEq
TLSH 9ED4231043261BEED6C3963F83468C8411EAF75C4EF5B62E9E2C7B2DA4F094D19CCA56
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: ns5.bilsay.com
Sending IP: 89.252.181.244
From: <arma@armaltd.com>
Subject: Inquiry// Meeting Table// Final Payment
Attachment: drawings and specification contract.r00 (contains "drawings and specification contract.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-17 13:55:13 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 efdd71930b1035b643332384adf41e59f6ca280bd9b4a922bad7776d0410ab51

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments