MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c3db32b517818d3088ae692e190378a0a989bd3c3c211348ea163191082cf77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0c3db32b517818d3088ae692e190378a0a989bd3c3c211348ea163191082cf77
SHA3-384 hash: bc51be2118e1d86a41eb8c2209a80e6939cb3183133083508437ec00ca579c9126c86d1d620b0c736c2e4545ab8c25b4
SHA1 hash: 73c8d46194356a09501337bf0c9efda9032b68e3
MD5 hash: c4fef1f3d09d47226897098738589c08
humanhash: football-edward-zebra-magazine
File name:DOCUMENTS.r00
Download: download sample
Signature AgentTesla
File size:334'743 bytes
First seen:2020-08-14 08:52:17 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:wPdmQtrV5J+WF6eWi+HYVaHNKmLwOr3mTffyxr/tbzwK1cqaD:wprl+WF7epHomXy7fAtb3KqaD
TLSH 3F6423E6704A1AAB8DCA0CF73711B5E32A6158E6F0B132BE6D10FF1F053DD946C58265
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.mawaqaa.com
Sending IP: 69.0.149.219
From: <sheref@swtt.com.kw>
Subject: FW: FINAL SHIPPING DOCUMENT/DHL
Attachment: DOCUMENTS.r00 (contains "DOCUMENTS.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.SmartAssembly
Status:
Malicious
First seen:
2020-08-14 08:54:06 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 0c3db32b517818d3088ae692e190378a0a989bd3c3c211348ea163191082cf77

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments