MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fb4762ce04b0f359557a846327f46ca123d17c67f651dd8780078397eff7d96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1fb4762ce04b0f359557a846327f46ca123d17c67f651dd8780078397eff7d96
SHA3-384 hash: da30b94e30ddd4a0bd2f3c575e3d402bea51f1c3bee334764e99e86dfb2658e10643e5d8113cb9b4b6656543fcfa7e19
SHA1 hash: 8d0c8e70b4723693b2dc7d8d3c1ce41f3fc735c5
MD5 hash: e9e36e41517c5eafdde913d413018b8e
humanhash: hydrogen-victor-carolina-georgia
File name:240-20200710-373063-ADV.GZ
Download: download sample
Signature AgentTesla
File size:343'240 bytes
First seen:2020-07-10 09:15:23 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:exJ3Yqwpb07VUqLcNUpPu3QCkIAGqSwXWKnnYpKDlrW+JrbsGPzEEv:+ox507VUqLRK0zSwm4n3rWErb5PIM
TLSH 1A7423AEE06D4DA77F816ECFD1A4844FC152E13184C5B963E10AB36ED1ACA34A3F9314
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: CL0069UA-SG4.WEBVIS.NET
Sending IP: 203.142.16.158
From: DBSeAdvice@dbs.com
Subject: Transaction Advice / 17042
Attachment: 240-20200710-373063-ADV.GZ (contains "240-20200710-373063-ADV.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-07-10 09:17:04 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 1fb4762ce04b0f359557a846327f46ca123d17c67f651dd8780078397eff7d96

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments