MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e0b2029403faff945d82768f2442f70392b943e358611b7e70ca5eec5ddf47a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1e0b2029403faff945d82768f2442f70392b943e358611b7e70ca5eec5ddf47a
SHA3-384 hash: ce56fa8716125885f20cabad29722eb25e1387d2ad3d644f17b742088d8c12552f6005b16eb9ae1fe8fa34f6898dd399
SHA1 hash: aecdcd256e849893547cd414c8c8ff7a9f049f0d
MD5 hash: 671e4985cf1b6aedf9802092b9fcb36d
humanhash: double-eight-pasta-early
File name:Order0023903.zip
Download: download sample
Signature AgentTesla
File size:407'459 bytes
First seen:2020-06-18 06:12:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Aw3rItph1qaDDRe+jQbpf7GZqsPQypfndyfeXPCK2hPtmxPXStvxy6SSB0C3YAGs:f7IHDReuaRD2QyBsfw6Po5XKJJSl+JSW
TLSH 6E8423229DEBE6D731410424DE910DE99238DCF89A30B7D377D2C10C16ABA5AD6C2F2D
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: antirelay46.smtp.cz
Sending IP: 81.95.105.176
From: vyroba@oceng.cz
Subject: Order# 0023903
Attachment: Order0023903.zip (contains "Order#0023903.exe")

AgentTesla SMTP exfil server:
mail.ab-care.eu:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-06-18 06:13:12 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 1e0b2029403faff945d82768f2442f70392b943e358611b7e70ca5eec5ddf47a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments