MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2403bc9c9f870f068861e768c3be3ad92a6197d21bf96246b63cfb053abe0cdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2403bc9c9f870f068861e768c3be3ad92a6197d21bf96246b63cfb053abe0cdc
SHA3-384 hash: 7e3af4dc6439735ad0f8de6fe7d50abfd839c62f40a89441b7846adb709a3bd91faefb1d53a0b8e5502299bb0f18a875
SHA1 hash: 7d986bf53a961c49fc834de4ccb248dcadd3ff05
MD5 hash: 67180c88aad900d1474e968e14d80589
humanhash: black-wisconsin-six-cardinal
File name:orden.zip
Download: download sample
Signature AgentTesla
File size:403'802 bytes
First seen:2020-06-25 07:53:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:PV7l1B09BghE7AxwbHAjU7TPHlBMVhwA0z/x5u:PV7lXhLabg0PHHMVhwvz/Xu
TLSH F78423616D4AA60A72821C1F7F8BF2FD6944CD34A35748329B6DCEE4C4AD26F420ED17
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fre.freespirittours.ge
Sending IP: 192.254.140.61
From: Claudio Lang\ Metalurgica Arauco <adquisiciones@metalurgicaarauco.cl>
Subject: orden
Attachment: orden.zip (contains "orden.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2403bc9c9f870f068861e768c3be3ad92a6197d21bf96246b63cfb053abe0cdc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments