MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0010ffc689365b3eb8bb323cbbb02de784b8a62d633c835b72972f41b171b8d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0010ffc689365b3eb8bb323cbbb02de784b8a62d633c835b72972f41b171b8d0
SHA3-384 hash: ccf2c45fd5b2e6fe6437da106e17d88b81b4d74102ea17f95ab5050ce77ad4b4eb04c556fc47311801ef0e85f1c4ee7b
SHA1 hash: 1b363297c85d2d4c7901e7681fee99692a1a5d36
MD5 hash: b3b7d52f3297191487ed27b72bf94169
humanhash: whiskey-social-december-cat
File name:payment copy.xz
Download: download sample
Signature AgentTesla
File size:1'506'091 bytes
First seen:2020-05-19 05:46:23 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 24576:+w/azYOmcH21fEGhhb6iGMaQlMfCK2Zcmm/fdsaB3rNjwRfJaww/u02GhUYnQBJ/:+Ca8/A8hlKfL2Z+3ZmJnwG02GhUYnkJ/
TLSH 1A653363C946EF95AA88C1084D944653EBC4F4AC9625DA432A6BE2F21F4C50CFF24F5F
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: srv0.servermada.com
Sending IP: 46.16.202.48
From: Lyn <manilovg@yahoo.com>
Reply-To: uwalchevrolet218@gmail.com
Subject: RE:SWIFT ZA PLAĆANJE(PAYMENT COPY)
Attachment: payment copy.xz (contains "payment copy.exe")

AgentTesla SMTP exfil server:
mail.rajalakshmi.co.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.AitInject
Status:
Malicious
First seen:
2020-05-19 16:54:29 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

xz 0010ffc689365b3eb8bb323cbbb02de784b8a62d633c835b72972f41b171b8d0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments