MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05954232357b98d634ff3e9f30a5a8cd9db26355d0debc00bf3f6ca192c84749. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 05954232357b98d634ff3e9f30a5a8cd9db26355d0debc00bf3f6ca192c84749
SHA3-384 hash: 9aba26a4e05a0007d2e8f50ca9b1dee8d7364a3934a874dd72d749468f48117182439dc3c26e4603cd95412da831c4e9
SHA1 hash: 49ad3bd75924df347ed9b7a9a922408145fc46ca
MD5 hash: d3d0885decb45d79cb82779e791063a4
humanhash: timing-nevada-papa-bluebird
File name:revise pos.pdf.zip
Download: download sample
Signature AgentTesla
File size:437'435 bytes
First seen:2020-07-07 09:00:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:J9jqAFNSWYJthX6HsDDtB9sIWwtSkYYelJNykR:JH5eUHsDJB3PtSkYYiNh
TLSH AE942321457F1D3610E42E1268E3BA87CBD73FACC25FD31902926485C89462FA679FCE
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 142-4-22-49.unifiedlayer.com
Sending IP: 142.4.22.49
From: Purchase Manager <marketing@majbootmhe.com>
Reply-To: Purchase Manager. <marketing@majbootmhe.com>
Subject: Revise Pos - Break up details!!!
Attachment: revise pos.pdf.zip (contains "revise pos.pdf.exe")

AgentTesla SMTP exfil server:
smtp.mail.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-07 09:02:09 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 05954232357b98d634ff3e9f30a5a8cd9db26355d0debc00bf3f6ca192c84749

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments