MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5879e20336df8397c7f58a10924f1c5f421786057b92c2f2eb0266554cc2a46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f5879e20336df8397c7f58a10924f1c5f421786057b92c2f2eb0266554cc2a46
SHA3-384 hash: a75d35d9932c389f3d208b21e050669390b7fa59d1189bb1ce074fa7b26235f5990054a067939cf33857674a015d8891
SHA1 hash: 4520864cca80fa7502b56d613a3529ab16ed6d56
MD5 hash: 2002bde82b1c17d99005f5b4b0fe0e84
humanhash: georgia-twenty-cardinal-cold
File name:URGENT SAMPLES NEEDED.zip
Download: download sample
Signature AgentTesla
File size:521'248 bytes
First seen:2020-09-29 10:01:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:6/+OEck2TWo8ez5VQi8Pw86/59up5/fEb0LrR1bKPHp:6Kz25hzfQFJ6/59GxfEUHbK/p
TLSH 53B423211127697290DF8BD3626BDF6706F4E6644F0A29941FF66B578FF5C03B08A0AC
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Reinhold W. Heim GmbH & Co.<gabi.schroeder@rwheim.de>"
Received: "from rwheim.de (unknown [103.133.108.114]) "
Date: "29 Sep 2020 03:00:33 -0700"
Subject: "urgent samples needed"
Attachment: "URGENT SAMPLES NEEDED.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Androm
Status:
Malicious
First seen:
2020-09-29 08:30:01 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f5879e20336df8397c7f58a10924f1c5f421786057b92c2f2eb0266554cc2a46

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments