MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c619396fd146a0b351de1b4c380883037fc279ef10c62e16a5fbff8e5d3c741. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0c619396fd146a0b351de1b4c380883037fc279ef10c62e16a5fbff8e5d3c741
SHA3-384 hash: 8d742fcc3b02ff774c7c30533133070fee17070a6425ae2eb73fb8c72fa5f3202fc8eb9348454e9c056a368db1286de8
SHA1 hash: 4acdf35502899318b184becc0f356b88c1bb4083
MD5 hash: d0b05c17fab0305e2c644667e4639975
humanhash: timing-massachusetts-aspen-seven
File name:Disc FDBC 3658.rar
Download: download sample
Signature AgentTesla
File size:397'321 bytes
First seen:2020-07-21 14:08:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:dDwGQTmjs3x6tBHrDOCLmAp7C8jxi8UM8ayLyMLt0htzA1XzdWvwJPRYjkZx:dDw4sBALXLmAAkUM8TPyhtUfW4Wgv
TLSH FF8423E9C3955E76BF182C6B1FAF6509084113FDD7AD39E90B488931DB2B7052C908BB
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: jax4mhob20.registeredsite.com
Sending IP: 64.69.218.108
From: Fatima Ail <fatima@almaexpress.com>
Subject: SWIFt MEssages FDBC 3658
Attachment: Disc FDBC 3658.rar (contains "Disc FDBC 3658.exe")

AgentTesla SMTP exfil server:
smtp.epaindemgroup.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-21 14:10:08 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 0c619396fd146a0b351de1b4c380883037fc279ef10c62e16a5fbff8e5d3c741

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments