MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 190bb6bb870f97fe53743814a41e462a7f36544be6903745dcdb84151e28bc5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 190bb6bb870f97fe53743814a41e462a7f36544be6903745dcdb84151e28bc5d
SHA3-384 hash: 4f8046b51880cbfeafeca3814892fbc593bd23d7c2561fc3c1c914949853d65628dd5b818b061e1e1bf1fdb6dd728e8c
SHA1 hash: 96675d559de3787642615f5b7802739af7c11217
MD5 hash: a16ce9c4d0978782c677dddc89f40b78
humanhash: zebra-texas-gee-failed
File name:Facturas Pagadas al Vencimiento.r00
Download: download sample
Signature AgentTesla
File size:399'300 bytes
First seen:2020-07-16 10:03:36 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:5zmhxKBzYibMGpLYO8USFgGqb+u6yudDj6w90h4zH:otGMkYrtgGqCu6ygPr7zH
TLSH 6E8423E5B13D70EA82AE6AE1F625FBE089074200799205CD1925DEFDD4D035E2BDCEC6
Reporter abuse_ch
Tags:AgentTesla BBVA ESP geo r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: correo.natxo.cat
Sending IP: 81.21.67.230
From: Confirming.bbva@bbva.com
Subject: BBVA-Confirming Facturas Pagadas al Vencimiento
Attachment: Facturas Pagadas al Vencimiento.r00 (contains "Facturas Pagadas al Vencimiento.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 10:05:09 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 190bb6bb870f97fe53743814a41e462a7f36544be6903745dcdb84151e28bc5d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments