MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13a43b799628a39095e35b564fe64a755393a80936f9578d0596f7053d68a690. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 13a43b799628a39095e35b564fe64a755393a80936f9578d0596f7053d68a690
SHA3-384 hash: b0b2022fdc9d79eb8dd406c95582f72db73529b4cc8dd1287f096f7e09f6e9e6d27a8a5b371f8278acf694acca33420c
SHA1 hash: 151b6e2d1f9421df573bca19df68f8548ab69b81
MD5 hash: 8198da9c1dcd47cb681fb7f83cf02aaa
humanhash: leopard-victor-lactose-alanine
File name:profoma.rar
Download: download sample
Signature AgentTesla
File size:362'798 bytes
First seen:2020-07-03 06:24:24 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:4kp8PT0u4YSSVcJE4cwGWdg3KLJXfYONDM0yEB1LwL0WqQrcdIPfayAEGIdVsVbA:4kpAM3IwGIcSlfYgD3LWrcdoa2GIGbqt
TLSH D974235F9D56EC26D303A97FFB71B30DFA41754BA4A3B4D288B5DA0418601A86FBDC10
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fre.freespirittours.ge
Sending IP: 192.254.140.61
From: executive@freespirittours.net
Subject: profoma
Attachment: profoma.rar (contains "crypt.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-03 06:26:07 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 13a43b799628a39095e35b564fe64a755393a80936f9578d0596f7053d68a690

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments