MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ded368e22806efb40610217376eb8a052623394583906e07fcd0152363292a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2ded368e22806efb40610217376eb8a052623394583906e07fcd0152363292a1
SHA3-384 hash: 2be4263da57657b2d515d80f1f01e13f185c79e326c3f89299fa929991c4ebe6b110b35504d208c3a3671ca6c8217cf4
SHA1 hash: b9e8f47cc6311ea854fedd2c60965b2ec8d9cc66
MD5 hash: a76a08d1c33fcc5dab360a1890342edf
humanhash: freddie-lake-bacon-summer
File name:NEW PO-48002738..zip
Download: download sample
Signature AgentTesla
File size:1'157'888 bytes
First seen:2020-05-25 12:30:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:QfPl0BmEYP6saC6MTBizkgm23iCFwdLWEObNjYPMU:QKK6saC6MTs8C2ZWvbtYl
TLSH F93533D8B8EB44D4A2FD5B4C56F2EBB99410115804368E0D6C9C8CE06F9F8F16EF994E
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: crescentindia.com
Sending IP: 103.99.1.147
From: Purchase <purchase.cippl@crescentindia.com>
Subject: RE:Purchase Order
Attachment: NEW PO-48002738..zip (contains "NEW PO-48002738..exe")

AgentTesla SMTP exfil server:
mail.pptoursperu.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-25 12:36:50 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2ded368e22806efb40610217376eb8a052623394583906e07fcd0152363292a1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments