MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 331ea80d27c5da40c1477567abd7124c2e65d0ff805154bedbd21111a3d92eac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 331ea80d27c5da40c1477567abd7124c2e65d0ff805154bedbd21111a3d92eac
SHA3-384 hash: d6417f9ab7b7d0f634dbbe07adb6ddb9c3fb084c99f7e788df5257268d6a3185007e3493d384044d9ad9a6d52d7acc65
SHA1 hash: a94638e573244de63df8dc361135b025f3874825
MD5 hash: 8b1c47679d64f9ef799581d4d31273d4
humanhash: virginia-queen-hotel-washington
File name:New Order 000110.zip
Download: download sample
Signature AgentTesla
File size:1'067'243 bytes
First seen:2020-05-14 11:40:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:hq/g5BZefBeaDLIGdGRj8AtEFg9WUC7d9kMshnqSBt17NHO1NDOtVIgx:xPefx/zdgsSabkMwn/17U1hOtJ
TLSH CE353359AA281491B43BA2488EF6D3C6E0D6DEDA45123100FF6CFB8D697E50487F198B
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.ftcyazilim.net
Sending IP: 80.93.216.245
From: <info@onurtriko.com.tr>
Subject: FW: New Order #000110
Attachment: New Order 000110.zip (contains "New Order #000110.exe")

AgentTesla SMTP exfil server:
mail.elkat.com.my:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 12:35:48 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 331ea80d27c5da40c1477567abd7124c2e65d0ff805154bedbd21111a3d92eac

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments