MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 105b9ecf4676a67849fdddd7b3f1c1cc9ff80d4432a5ca0e3fcc9e2e6d64543c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 105b9ecf4676a67849fdddd7b3f1c1cc9ff80d4432a5ca0e3fcc9e2e6d64543c
SHA3-384 hash: a4e963384ea1a36f0339b4ba71073ab9e570d2016986c33d74586b311551ca03426af6227d747e184ea1f5185bed056c
SHA1 hash: 9e2597e2bc971f1ff9557277d62f32eabf5aa421
MD5 hash: 666c65c94e7abb091d0cbb9ddf8ffa09
humanhash: white-washington-louisiana-carpet
File name:NEWORDER.rar
Download: download sample
Signature AgentTesla
File size:927'790 bytes
First seen:2020-06-15 14:02:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:DP6S002d7o8cKlIbNlIgAoL0ccj5+EN1CRiSEzwpAjfmFFEjJ5QrXhl7feFO4Yq:WSTO7o8cKlsOvcQ1CoSzmrJqVJfeF1Yq
TLSH 1C1533FBDA199457FAF01B81EB81839E4528443BEC3114A6A294DDDDCD2AF013DAD2CD
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gfzy666.com
Sending IP: 47.52.131.24
From: KIM <admin@irisplaza.co.jp>
Reply-To: abs000010@outlook.com
Subject: Re: New Order
Attachment: NEWORDER.rar (contains "NEWORDER.exe")

AgentTesla SMTP exfil server:
mail.sanfusin.com.tw:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-15 14:04:07 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 105b9ecf4676a67849fdddd7b3f1c1cc9ff80d4432a5ca0e3fcc9e2e6d64543c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments