MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 19c652e3a4cf88cb969414c4ddbd9393b4739523211a27000504f981a6f1d364. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 19c652e3a4cf88cb969414c4ddbd9393b4739523211a27000504f981a6f1d364
SHA3-384 hash: 180448c579dc402ee0fa1df42f7c378e0bb10710426c774e950b8d82fa12fb125d79fac704b6f70d377c377d9c4ced46
SHA1 hash: fc716c6f69d79f4e298311c6b71f6f8c30c10555
MD5 hash: 3b06a3dc8afb040dc9588b4afdc5fe56
humanhash: fish-potato-july-network
File name:New Order.zip
Download: download sample
Signature AgentTesla
File size:487'349 bytes
First seen:2020-06-02 10:46:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:tWfI6EmKwVx0Wuq7CvYltMnUdst9mVyA700Z82:YImKpvatMnx9nAnZ82
TLSH 6DA42366C713158CB57C16D7B7EB9C7BCC3DAA68C32B132C9136122E1A2817C6C1E57A
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chapar01.afr.hezardastan.net
Sending IP: 79.175.191.243
From: Tina Halwani <fcopy1@dutahitajaya.co.id>
Subject: New Order
Attachment: New Order.zip (contains "New Order.exe")

AgentTesla SMTP exfil server:
mail.samudrapanel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Boilod
Status:
Malicious
First seen:
2020-06-03 04:02:26 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 19c652e3a4cf88cb969414c4ddbd9393b4739523211a27000504f981a6f1d364

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments