MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13a703589cf344ae48e5fa7e7f6047f5001d108888bff63645a2da27e3af7a7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 13a703589cf344ae48e5fa7e7f6047f5001d108888bff63645a2da27e3af7a7c
SHA3-384 hash: 89058ecde0007961db509f8cbe5f0f8e81a82fa6397dd7668cb2a8b70e9bf32bd8ec437b11f81b51188eae83e8f0a678
SHA1 hash: c7de6a678d2a7e6e9d1d2aa13613364ff1bf539c
MD5 hash: c43865a73afc1f45a631d1f2f759d7ae
humanhash: jig-mars-king-friend
File name:CHEQUE PAYMENT COPY.PDF.z
Download: download sample
Signature AgentTesla
File size:946'360 bytes
First seen:2020-05-01 12:24:48 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 24576:7Y+P7Uiz4vVjTqPhtZJByYBzfYaLm8Bze87uV:7TP7UvVnqPXhyyTLmBWuV
TLSH EB1533492535D8AA6BD43355281CBBD488C1CFE3E72DE18FA87A872DC2B4771CDA40D6
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.totkotomotiv.com
Sending IP: 185.178.45.189
From: CEO ACCOUNT DEPACTENT <nadine.paira-eugenio@treekangaroo.org>
Subject: CHEQUE READY DATED 4/30/2020
Attachment: CHEQUE PAYMENT COPY.PDF.z (contains "CHEQUE PAYMENT COPY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
853
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-01 12:35:45 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 13a703589cf344ae48e5fa7e7f6047f5001d108888bff63645a2da27e3af7a7c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments