MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 358a98399e29d8997197cf4146bfa8daddb136f6fb54597bedb5f654e5de1c60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 358a98399e29d8997197cf4146bfa8daddb136f6fb54597bedb5f654e5de1c60
SHA3-384 hash: 207bd996eeaa2d9504f82728808741ee8b7063cbb0f18e1ea2515f98ff9357d6eda2c1ac7c37800d98e4009c52be2e58
SHA1 hash: e1eddfcdcc062fa2e09710d5731dc99fa9576566
MD5 hash: 5b1d03796b0460c1a3d46b0824a56d52
humanhash: uranus-twenty-carolina-rugby
File name:Order FKL_pdf.rar
Download: download sample
Signature AgentTesla
File size:221'745 bytes
First seen:2020-06-29 06:19:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:0jyNsyS66hMwH78sbixCZmleUzFdW76XZohr1TMf:0v6+FixbAG/rohr1TMf
TLSH BE2423DEF53698DD5BC7FE7119B9B7E60402D9088989F8EAA12B2CFCC50C700EC95619
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mcegress-30-lw-16.correio.biz
Sending IP: 191.252.30.16
From: smtpfox-lwe2n@depositodebebidassantacruz.com.br
Subject: Re: rasterivač za krtice
Attachment: Order FKL_pdf.rar (contains "Order FKL_pdf.exe")

AgentTesla SMTP exfil server:
smtp.jixst.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-29 06:21:06 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 358a98399e29d8997197cf4146bfa8daddb136f6fb54597bedb5f654e5de1c60

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments