MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b1639aba8b802ffce62b362e90dd49a051795808ad9954e23c3cc770eda4069. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0b1639aba8b802ffce62b362e90dd49a051795808ad9954e23c3cc770eda4069
SHA3-384 hash: e10df281dcb55676ab809518d017a2396714a3cc4cc495bcf21f65b7df6dc1e77420a4e72ce408ecc1fe0098c8640db1
SHA1 hash: 6dac5bef0d72c2077fc9e83cc7b49bb340a9c630
MD5 hash: 804f5b51e5a9372105251a8b99846c78
humanhash: illinois-sweet-mobile-oranges
File name:S2020000003209.r00
Download: download sample
Signature AgentTesla
File size:1'270'139 bytes
First seen:2020-05-07 06:48:01 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:qSEkvZFTOE9QAUfkawwKeJsYPw1hGkr7PPwvfhxFFtd54dMIYewJhl7:BEkXK+NauwVJqg67OxFoFYewPF
TLSH 0E45336A8A843D8E9FCC08E36085F74AFDA6467F9A7D4F1DA03289FBD0D146156D1C8C
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: jjb.cn
Sending IP: 156.96.58.98
From: sales5@jjb.cn <sales5@jjb.cn>
Subject: 索取样品报价
Attachment: S2020000003209.r00 (contains "S2020000003209.exe")

AgentTesla SMTP exfil server:
mail.hakanmobilya.com.tr:587

AgentTesla SMTP exfil email address:
tulayo@hakanmobilya.com.tr

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-07 00:56:24 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 0b1639aba8b802ffce62b362e90dd49a051795808ad9954e23c3cc770eda4069

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments