MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a4d7ec849e9bd56b0bb7c309e9404b9ea6638c75322e625ea4fea37432742f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2a4d7ec849e9bd56b0bb7c309e9404b9ea6638c75322e625ea4fea37432742f1
SHA3-384 hash: 76281f380199350a9f1cbc81c29537d2c0ef36111cb2f3b39896a19f874270bb7cc9c6d4f2af7b497e3554ce35f238be
SHA1 hash: dde97ebd79c62450d451a76e38978ff5c2469ac9
MD5 hash: d64fad9ae058769bd940f09662b7c71f
humanhash: nevada-virginia-september-pip
File name:PO AO-200402_pdf.zip
Download: download sample
Signature AgentTesla
File size:1'073'056 bytes
First seen:2020-06-08 12:37:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ZJOR0ivguE3bRMlM0YVEbAy6QQgTY5LhpXv246kHRsGUd1cpKHW0AyzVf04sbvZv:LgtvgTtEXhn6Q7ed9U0yOXSHgVYJO
TLSH 8735237AE07477E3C79DF69902A2B3972545324C91ED0780336E3EBA9614478A1B29FC
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 1asalldirect.com
Sending IP: 103.99.1.147
From: kenny<kenny@1asalldirect.com>
Subject: RE: Urgent Request For Qoutation(RFQ_#20200219)  
Attachment: PO AO-200402_pdf.zip (contains "PO# AO-200402_pdf.exe")

AgentTesla SMTP exfil server:
mail.parshavayealborz.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-08 12:39:06 UTC
AV detection:
22 of 47 (46.81%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2a4d7ec849e9bd56b0bb7c309e9404b9ea6638c75322e625ea4fea37432742f1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments