MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35661f6ed8f27a785f94fb0cae9837ef49fdfbd872d14a40c83f25c26f5613b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 35661f6ed8f27a785f94fb0cae9837ef49fdfbd872d14a40c83f25c26f5613b0
SHA3-384 hash: dc01b3d2f9a0e55d7be0894f5e8c1a77f73d9886d5250d41240c84b712dbcd60e41e855c496508fbfa8cdec21f04e9b0
SHA1 hash: dacd7b5c9973588cce576ee4fa9af276aa1b948d
MD5 hash: 2abfa7a6a3b75fed709e94e24ba066d2
humanhash: artist-spring-emma-mike
File name:SZÁMLÁK ÉS SZÁLLÍTÁSOK.rar
Download: download sample
Signature AgentTesla
File size:532'395 bytes
First seen:2020-07-09 12:18:27 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:mggdI1Fprd1TFrY515+KOdQ05AI2wLyZ2xcaAlIh/k79:m3dILpR1BrUjFOd3AI2w2PlI+B
TLSH 29B423F2000A4EA109879C686A7EC6D929A5FECC90BEC7AF9C6BDBCD3101C445C5DCB5
Reporter abuse_ch
Tags:AgentTesla geo HUN rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: tambay1.ixirdns.com
Sending IP: 85.95.241.148
From: Austro Diesel Hungary <istvan.fekete@austrodiesel.axelero.net>
Subject: SZÁMLÁK ÉS SZÁLLÍTÁSOK
Attachment: SZÁMLÁK ÉS SZÁLLÍTÁSOK.rar (contains "SZÁMLÁK ÉS SZÁLLÍTÁSOK.exe")

AgentTesla SMTP exfil server:
mail.vinorema.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-09 12:20:06 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 35661f6ed8f27a785f94fb0cae9837ef49fdfbd872d14a40c83f25c26f5613b0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments