MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ef44835affd01422b98be05f7d20c2a04ffd3a0c9dd7e7b8dc6d7e22ecee864. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 0ef44835affd01422b98be05f7d20c2a04ffd3a0c9dd7e7b8dc6d7e22ecee864
SHA3-384 hash: e82ec50fd668d556cc7c780c63be23e0824f75e62b2a1e6de1be5607d757bd2ea665c73eaf40b51f5ecde133fa08b07f
SHA1 hash: b9e65c7b1e60f5a1a0622432db4337f3cd0155fc
MD5 hash: 970cd2382074540f8c1750425e6744d1
humanhash: music-asparagus-network-batman
File name:BL Draft-2020-39883.pdf.gz
Download: download sample
Signature AgentTesla
File size:590'582 bytes
First seen:2020-08-31 06:24:11 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:B8CTmQbQS6WjnNS3cowTQzBxjWWgPIm4RjyAZXbPKXrFdDYBDqWcT7mEaW:4QbQS39YB8WgPjqyAZXOXz0IWcT7m2
TLSH 36C423CA7F24E9F53D44DEA498532E9517F4FC5A03B9E4BC213B7C2861D182CB866A4C
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: maiair.com
Sending IP: 209.58.149.66
From: Helen Feng <bookings@maiair.com>
Subject: Re: **TOP URGENT** Shipping Documents
Attachment: BL Draft-2020-39883.pdf.gz (contains "BL Draft-#2020-39883.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 0ef44835affd01422b98be05f7d20c2a04ffd3a0c9dd7e7b8dc6d7e22ecee864

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments