MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0603f5490ac673492c235782c9896d89f5a43cc7687c62835937cd66fad4dd1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0603f5490ac673492c235782c9896d89f5a43cc7687c62835937cd66fad4dd1e
SHA3-384 hash: 7040a8239c80b1bc0a7bcfcf37b4ae6358059c5188b3f5b711faec8943a29f5d180bdb97f2176bf0ac62b47d92a90407
SHA1 hash: 2590d136f65bcb1bba09ff05a755fcad1debc89a
MD5 hash: 2087096ce7d3e91160772faaecfac9ce
humanhash: freddie-low-hotel-cola
File name:we-001.pdf.rar
Download: download sample
Signature AgentTesla
File size:520'717 bytes
First seen:2020-06-09 06:38:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:zbZYcJVUs3PL4jzOddv6VJ0yZPJMjET4np1jS6Z5:zbZYcTzPL4ov644Mj84phS6P
TLSH 16B423ACB71DAADC2BDAAB8E5C46E3C2105B4D7C1095CCCC4733C5183AE2579D9E9C29
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cimb.com
Sending IP: 103.99.1.173
From: Mohamed Haneef<cimbsponsorship@cimb.com>
Subject: RE: PAYMENT NOTIFICATION FOR PJC/MG/2020/L0116217
Attachment: we-001.pdf.rar (contains "we-001.pdf.exe")

AgentTesla SMTP exfil server:
mail.pro-powersourcing.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-09 06:40:06 UTC
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 0603f5490ac673492c235782c9896d89f5a43cc7687c62835937cd66fad4dd1e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments