MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 313852ed9012fd481b1ec97b3d22687d4d224c9e8d064b373be7013d94bf45ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 313852ed9012fd481b1ec97b3d22687d4d224c9e8d064b373be7013d94bf45ae
SHA3-384 hash: e3479dd7d2c0b9d09af60f79906fd808ca03b25cccde1e12dc8bfcf584f1f495a26b7c0d71312bf1cfb6f3aa0f8340a7
SHA1 hash: eb740ccc4f4c7018fc78bb0f3c38794469d9166f
MD5 hash: 07dc5ef9b36a04978b804bebb4392012
humanhash: maine-rugby-florida-cardinal
File name:Order001-000000845757LPO.XZ
Download: download sample
Signature AgentTesla
File size:1'040'823 bytes
First seen:2020-05-14 05:58:53 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 24576:NyWNOGGo029F3X8ZoAoR2Ae0LxGqRN2gNHtdY5eEiUt:NyW4PoNX+oAVAewx0gNNi5eE5
TLSH 322533AF547CEC75D30D9AA7183201F767EE3D8F589E682443C089D0D3AD1A27BC2A59
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hws-01.subisu.net.np
Sending IP: 202.63.240.138
From: neelam@ncbl.coop
Subject: LPO
Attachment: Order001-000000845757LPO.XZ (contains "Order001-000000845757LPO.exe")

AgentTesla SMTP exfil server:
mail.elsewedyindustrial.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 06:37:02 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
15 of 30 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

xz 313852ed9012fd481b1ec97b3d22687d4d224c9e8d064b373be7013d94bf45ae

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments