MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f517085c06a8fbdc4b83932bbc7b00024d3b47e4d023faae3051284b68600959. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AsyncRAT
Vendor detections: 3
| SHA256 hash: | f517085c06a8fbdc4b83932bbc7b00024d3b47e4d023faae3051284b68600959 |
|---|---|
| SHA3-384 hash: | e03742b7abf3400339cbfd2c90a8c3d99efa3e9db0290fe01b3e147cbbe603b98e3ac06fb4f8c2575b4ff0419cece7db |
| SHA1 hash: | 718fa78d517c4479b5bfbe141fe0057ab3dbd621 |
| MD5 hash: | bd5a3d9fd6edadeb766648eecee9d6be |
| humanhash: | enemy-quebec-king-harry |
| File name: | WIRE_CONFIRMATION_USD_CURRENCY.zip |
| Download: | download sample |
| Signature | AsyncRAT |
| File size: | 69'131 bytes |
| First seen: | 2020-10-28 08:48:33 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 1536:FjUahWfxxLOF2ZuOHw6tnHv3yzxwt1Yvsh3Hy/0Ny:Fj+nLOFyN1v3sKYYNy |
| TLSH | 9D6302A1743AA748B967E0CCC856255D5737AFEE821E362B0BC80BF1D505D5DEE03C64 |
| Reporter | |
| Tags: | AsyncRAT zip |
abuse_ch
Malspam distributing unidentified malware:HELO: bestocean.com
Sending IP: 103.150.187.47
From: Ellen Tien (Accounting Dept) <ellen.tien@bestocean.com>
Subject: Invoice-WIre Confirmation USD45,909
Attachment: WIRE_CONFIRMATION_USD_CURRENCY.zip (contains "WIRE_CONFIRMATION_USD_CURRENCY.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-28 07:22:01 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.