MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 295d719fd1159cf7c734155ee5cf35cff77cd58e45949bbfe0e5f5ed878e673a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 295d719fd1159cf7c734155ee5cf35cff77cd58e45949bbfe0e5f5ed878e673a
SHA3-384 hash: d23e6a073f78c66eac6c161e949adf75b9d3387a00734ba4be84823d86117fbf83190d2da4c5c470d70726b4632be897
SHA1 hash: 1226ca1ef34079c659f63e639d7b0783e3eca3b7
MD5 hash: 7a02580af880a4a1c1d57b5878692a02
humanhash: double-item-charlie-floor
File name:Proforma Invoice INV9654.PDF.r24
Download: download sample
Signature AgentTesla
File size:580'557 bytes
First seen:2020-08-14 08:11:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:c/yuzeQ3UfulP+OcSkTz3DEqf4Nmx/YkFxjk9xFmnToM3i+UaYO89:c/yweQkcP1jkTzzDcmJyNmn0M3Kay
TLSH CCC4231A4F30CE77FE5691E8A015F623D087A357791E5CE68FA420B1DD98586807C8FE
Reporter abuse_ch
Tags:AgentTesla R24


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.systemmekanik.com
Sending IP: 151.106.3.198
From: Yeşim ALBAYRAK <yesimalbayrak@albayrakbeton.com.tr>
Subject: Official Proforma Invoice for Bank enclosed To victim-email
Attachment: Proforma Invoice INV9654.PDF.r24 (contains "Proforma Invoice INV9654.PDF.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-14 08:13:09 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 295d719fd1159cf7c734155ee5cf35cff77cd58e45949bbfe0e5f5ed878e673a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments