MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11f70e938288e4c34cd17d12ea9eb5fe81564fe0a5b1f20ce687b9203230186f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 11f70e938288e4c34cd17d12ea9eb5fe81564fe0a5b1f20ce687b9203230186f
SHA3-384 hash: 8cc5503d9d1de327efe77ed154704ce32949526faafa1d6c96ff7b3cd8c994a3d967bb26043c924481d92e79592470f3
SHA1 hash: fa79d39a187111b2f75be1c0c971cff60f7459ac
MD5 hash: d677d7f1fee48a210ae621d1cfdd998d
humanhash: green-sodium-montana-mississippi
File name:Cancellation of Cheque payments Due to Rise in Covid-19.rar
Download: download sample
Signature AgentTesla
File size:414'893 bytes
First seen:2020-04-15 11:19:09 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:KvN1pYyWFMhdCLORsCdhsy+2HLt4CFwrdVMv3vWbQXJU:6WnMhdCNgW2HBFAqfWWu
TLSH 2A9423F972867C96D5CF31C5B44C9824DD933E76FA10A4260CAF224E2971DB6B7488B8
Reporter abuse_ch
Tags:AgentTesla COVID-19 rar


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: linux947.grserver.gr
Sending IP: 178.63.13.15
From: Emiratesnbd Bank <elly30478@gmail.com>
Subject: Cancellation of Cheque payments Due to Rise in Covid-19
Filename: Cancellation of Cheque payments Due to Rise in Covid-19.rar (contains "Cancellation of Cheque payments Due to Rise in Covid-19.exe")

AgentTesla FTP exfil server:
ftp.dv-panda.hr:21

AgentTesla FTP exfil username:
mani@dv-panda.hr

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-04-15 11:35:25 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 11f70e938288e4c34cd17d12ea9eb5fe81564fe0a5b1f20ce687b9203230186f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments