MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 384e91f0cb36b240acbc24da8977c4dd3dc2938f05c6b4b83f3d95c7efef2d03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 384e91f0cb36b240acbc24da8977c4dd3dc2938f05c6b4b83f3d95c7efef2d03
SHA3-384 hash: eff43c54d77048f0f5fe0c1db39da0b41723f78653fb54ff2f1b7a217fd525dc3c1f81d0d40be802a2b8fe4b9a327680
SHA1 hash: 040710379a50d4f6af32602fc0db19a504ae8250
MD5 hash: ab2f25ac1eefccd431cbb8f6f9778dac
humanhash: blue-arkansas-connecticut-low
File name:Order.pdf.cab
Download: download sample
Signature AgentTesla
File size:226'885 bytes
First seen:2020-06-29 06:43:25 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:UfX8466RvLk7j4q0/RCtn2JPL1ujHZD9JgvM:OM4Fv7RRVEFDc0
TLSH 1E24236A406E1393C951E925117D7807960DDE8C9CCCE323FDA184B1A01B8BAEDCE7F2
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.pimskools.ga
Sending IP: 86.104.194.97
From: Sales <Swift.mails@protonmail.com>
Subject: Fwd: Order
Attachment: Order.pdf.cab (contains "BL_INVOICE.exe")

AgentTesla SMTP exfil server:
mail.napred.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Tiggre
Status:
Malicious
First seen:
2020-06-29 06:45:06 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 384e91f0cb36b240acbc24da8977c4dd3dc2938f05c6b4b83f3d95c7efef2d03

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments