MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a3fc4a029ef1aec1091a0f6f006543887e3d2e8a29fea151a7ca758cdc5fb59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a3fc4a029ef1aec1091a0f6f006543887e3d2e8a29fea151a7ca758cdc5fb59
SHA3-384 hash: 59ea5c60ddecb701b0b8ecc25b4824370ca10907c37841d7b9e318b1627e192153f1aa26823ac60c6babf9e1d43da187
SHA1 hash: c497305496196121e5fd4b3ee1a62d269f2f446e
MD5 hash: 1535c3a727cc072ef1f45218ea311458
humanhash: idaho-fourteen-nineteen-diet
File name:paid invoice slip.z
Download: download sample
Signature AgentTesla
File size:379'464 bytes
First seen:2020-06-29 05:59:05 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:+PHEmy2i5vxGlER9XIHrIciO3cgOxFQ1gZYyTw/JWcPKZjU7wkpFM9A6o013C:+vvi7Ge3XIHrpiOiFOxyTNcPKZj5KFMm
TLSH E98423D9B7C372DD41E0FD880BEC85FDE66C8A013A8124D6D6A30285475CFAF9E691D2
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: alkuhaimi.com
Sending IP: 209.58.149.71
From: Accounts Department <rud-division@alkuhaimi.com>
Subject: paid invoice
Attachment: paid invoice slip.z (contains "cfr1eXQhvpq1qbj.exe")

AgentTesla SMTP exfil server:
mail.sensar-light.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-06-29 06:01:03 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 0a3fc4a029ef1aec1091a0f6f006543887e3d2e8a29fea151a7ca758cdc5fb59

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments