MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2eb3807956289bb22b4a54c110ccc0587090fb814148048d80aa677c8e5b2eff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2eb3807956289bb22b4a54c110ccc0587090fb814148048d80aa677c8e5b2eff
SHA3-384 hash: e0ef3fe405371da4489254b3127b17bc0a7fbe0a8155755d7c4441496ed1ec20e37c10c0a0e5ae71ac9b2c2ceba83945
SHA1 hash: 93b0715701aa58ffcbde40c5e5415af225042351
MD5 hash: f6f9175c0b08ae364a95128d29d00e2c
humanhash: diet-pizza-bravo-double
File name:PO pdf.zip
Download: download sample
Signature AgentTesla
File size:421'059 bytes
First seen:2020-06-25 09:38:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:w2TQxNGVlUONiv3ERSkfJ1D5NlDTg64rtF4:ww9NA3dkxLTgBpy
TLSH C694234F930FD52A804987F0053D35260AFA51F2D6ACFC8B9DA1069DABBD7AD10743B6
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sappi.com
Sending IP: 37.48.85.240
From: Mingzhu<sappipolicies@sappi.com>
Subject: Purchase Order
Attachment: PO pdf.zip (contains "PO pdf.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2eb3807956289bb22b4a54c110ccc0587090fb814148048d80aa677c8e5b2eff

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments