MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30b310897e709dcf774a92acdcf128d2e66f4c39d750e398ef2ea4468203e48d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 30b310897e709dcf774a92acdcf128d2e66f4c39d750e398ef2ea4468203e48d
SHA3-384 hash: 1866a2dc4ad80479a5495b346d3646e8c1b6086f7a89cb965b99c8ff90ea329b1e4b5c4c836098beb9aea797602da070
SHA1 hash: 56f0062249742a90ddc1408ab9db93473d3f84e1
MD5 hash: 73a7414a1a50afb0e223f0d99ff721fe
humanhash: fish-steak-ack-snake
File name:MV EVIAPETROL V TRADER.cab
Download: download sample
Signature AgentTesla
File size:790'541 bytes
First seen:2020-07-20 10:00:17 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:xKLOkwZ3UfkbRjmRAuBAGyXFtY9B/IUGW/iFrqHnWYn6CeKIAH0kQKONMqHwWeAc:09w2fY1GAscmJ5GfFrrOH0kSteQ+
TLSH 03F423D74D5480CD576A03521065F46E2132B3E77BB85E31EC12EC6BE2C0BAB6AE3C59
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mm0.805.biniomunidos.gq
Sending IP: 46.101.248.39
From: SMC Marine Management Pte Ltd <rifai@smcmarine.com.sg>
Subject: Request for Quotation - MV EVIAPETROL V TRADER
Attachment: MV EVIAPETROL V TRADER.cab (contains "MV EVIAPETROL V TRADER.exe")

AgentTesla SMTP exfil server:
dituae.com:587

AgentTesla SMTP exfil email address:
itsupport@dituae.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-20 10:02:05 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 30b310897e709dcf774a92acdcf128d2e66f4c39d750e398ef2ea4468203e48d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments