MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3954b8d1d14628945d2184d418b7b664c832449a09a90d98525e5a16323ea399. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 3954b8d1d14628945d2184d418b7b664c832449a09a90d98525e5a16323ea399
SHA3-384 hash: 44fc1e3734c3e822cd519ebbd326c5c02af90b823a4ed8883bb58b41a56d6fe42c065e670650c7aeb1892749388ef332
SHA1 hash: 6210f1d1bd3d8d379bba2542187493802434d269
MD5 hash: 5d6e5d5794656a579fee4c7e2547187b
humanhash: dakota-fruit-bakerloo-lamp
File name:price offer.pdf.r00
Download: download sample
Signature AgentTesla
File size:953'504 bytes
First seen:2020-05-25 12:51:33 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:WButgWpFLb+elqCAfd8osOLGVz4datoUN/OMuZiyu14/b:WBuyIFuel1AzsOO4daKMdynj
TLSH 6A1533D5E3412C44AE49FAA36B3F993A90C40E8B7F7A1967EF14F72648073136E7441A
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zeus.riff.ro
Sending IP: 81.180.116.49
From: Kinga Székely <k.szekely@duna-drava.hu>
Subject: DUNA-DRAVA/#01730 - 25.05.2020
Attachment: price offer.pdf.r00 (contains "price offer.pdf.exe")

AgentTesla SMTP exfil server:
mail.brymormaks.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Predator
Status:
Malicious
First seen:
2020-05-25 13:36:45 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 3954b8d1d14628945d2184d418b7b664c832449a09a90d98525e5a16323ea399

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments