MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fc858267612890e9b62ed3293fd56ed577b3e15bc1de5ec95505b1e319195dc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2fc858267612890e9b62ed3293fd56ed577b3e15bc1de5ec95505b1e319195dc
SHA3-384 hash: a228ad77ff128f565f718afade495e3ff0a379e54eb27ae782ffa8d2ee161b3a26c733743afcab45202860f0d6254232
SHA1 hash: 5756e5ef1857e8cf60d6bac06bfa45fbb1759c77
MD5 hash: 1b252bb021442a9809a1fd97b410154d
humanhash: lion-whiskey-pip-jersey
File name:Remittance Advice19062020,PDF.UUE
Download: download sample
Signature AgentTesla
File size:266'375 bytes
First seen:2020-06-21 07:01:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Igk8qahDKJTNUtoUU0CW4qfPzA5AsdW96RY2TWc2756b:IgkvQK9OtoUU0C/qfcSq+yY2Tj3b
TLSH D5442337D60D220B20FB668C0A4A5A14DB546CF4ACCCDE2A67F516391D01F47759B6CC
Reporter abuse_ch
Tags:AgentTesla uue


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: alias1.industralnews.com
Sending IP: 194.34.249.254
From: Accounts <info@industralnews.com>
Subject: Remittance
Attachment: Remittance Advice19062020,PDF.UUE (contains "Remittance Advice19062020,PDF.exe")

AgentTesla SMTP exfil server:
mail.marketinfosales.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-21 07:03:03 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2fc858267612890e9b62ed3293fd56ed577b3e15bc1de5ec95505b1e319195dc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments