MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33251a8ad33189f33a226f30c79948f6e810bccf58469ef1677b1568fd2d464a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 33251a8ad33189f33a226f30c79948f6e810bccf58469ef1677b1568fd2d464a
SHA3-384 hash: 73622c64b1ec0e0579e529b6f991bc43711d113ae3e21b5a00a931997fcafdbad59c3ae605ea3888a5018de9982f29e9
SHA1 hash: 0cc8d40ab334a99a31295926c827fc945b0a1221
MD5 hash: 1c53acabdda773ae543130a0af20ac32
humanhash: california-oregon-wyoming-rugby
File name:SOA.zip
Download: download sample
Signature AgentTesla
File size:391'666 bytes
First seen:2020-07-16 06:56:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:D3G1ca1yJPbXUTYmkC6prYnm0u81xMeIJAqs3KwBfSTuEmMF0o6VsZOjaPeIz:D21cwyJzXXmk2nflMPs3pSLmM6o6V1a3
TLSH 93842316D857CB2067AF8A5A604A0A24EE9B8B8875357FC43A19D135E272FC43D873D3
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 126.com
Sending IP: 103.99.1.174
From: Ningde Xinha<xhagent@126.com>
Subject: RE: RE: SOL SHIPPING - MV FENG ZHI BAO + MV CREST CRANE - SOA PDA SETTLEMENT PAYMENT
Attachment: SOA.zip (contains "SOA.exe")

AgentTesla SMTP exfil server:
mail.a-k.co.ir:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 06:58:05 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 33251a8ad33189f33a226f30c79948f6e810bccf58469ef1677b1568fd2d464a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments