MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0d31921b4742a6a40b17d509ee2f5d47b61c2a2e1e7d2c82bc0c6922382e2eb4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 0d31921b4742a6a40b17d509ee2f5d47b61c2a2e1e7d2c82bc0c6922382e2eb4 |
|---|---|
| SHA3-384 hash: | ad24869abf887dcf87ae842884aa22ce112891ac200f96919511bd1e3b4e7bd143f3a5831ea9252837fe0853b0e9dd51 |
| SHA1 hash: | 67b9748b42744fa84eb3f40539923e24ec04e748 |
| MD5 hash: | 01ed86dadf79818a639e87881ee3bb30 |
| humanhash: | potato-bulldog-india-lemon |
| File name: | PO2362542.7z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 436'001 bytes |
| First seen: | 2020-08-04 06:40:03 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:4fDGclt0IUyf4p7qf/S1R04szyev6iAJgU4Mm:hclqQ5Sn0r2ev6ror |
| TLSH | 7894235E89B25B158184F4325B8702CFCA453EA19093BC32DDDD844EC6F4ADFA63D89B |
| Reporter | |
| Tags: | 7z AgentTesla |
abuse_ch
Malspam distributing AgentTesla:HELO: slot0.glogerk.com
Sending IP: 104.168.236.67
From: Sam Karow <samuel@glx.sk>
Subject: Revised - PO QTY
Attachment: PO2362542.7z (contains "PO2362542.exe")
AgentTesla payload URLs:
https://paste.ee/r/8gpNi
https://paste.ee/r/mKywk
AgentTesla SMTP exfil server:
smtp.gmail.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Povertel
Status:
Malicious
First seen:
2020-08-03 17:05:45 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.