MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1eb864af99ab0c153ab7224bd5bf0d6dfc42ee8e45fc6fcdc3c4ec55f10c6be8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 1eb864af99ab0c153ab7224bd5bf0d6dfc42ee8e45fc6fcdc3c4ec55f10c6be8 |
|---|---|
| SHA3-384 hash: | 48855dae6308a8a927fcdbaaa05e27f5c8ec83268f95a60edbcb8b5c50227392fc6689a2e7cb229abaa7c12df7ae57a8 |
| SHA1 hash: | 6c525cfcae3cd47c86aee3de3c430d6897495e07 |
| MD5 hash: | 5152a90f66e491ff179394c274d97b62 |
| humanhash: | fish-video-sierra-saturn |
| File name: | ORDER FTH2004-005.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 433'658 bytes |
| First seen: | 2020-07-21 07:41:54 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:60tPPW4ouyqHpdAsP8ruAcltgHrUD2jjz1QmTNSIiXH:RtPPW4lTpaopILZfTNXiX |
| TLSH | 809423AC4001E6DCEEEDF76BC94CF1B8FDC845679906FE81E7126A0E96B424D6789007 |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: mail0.711.gillonuminno.ml
Sending IP: 142.93.134.62
From: ACCOUNTS <tiramaman@analjenafar.com>
Subject: Re:Order FTH2004-005
Attachment: ORDER FTH2004-005.rar (contains "Urgent Bid for Quotation.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-21 07:43:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Unknown
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.