MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a1869a3ad86bca973acdc80ccc9ae81735117dc0a29a584d5d1db0f8c09a1b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3a1869a3ad86bca973acdc80ccc9ae81735117dc0a29a584d5d1db0f8c09a1b0
SHA3-384 hash: 8e52bc56836374a147209729d464908c034384f48e9b750e7d39904c29c5716a50555a0a42912f878e4c9d1bc6496af2
SHA1 hash: b67620f81796a566146b35ba9ad9bcb8979a77b2
MD5 hash: 38d9cabb0f2627a11f2c053ff000f95f
humanhash: summer-oven-venus-fillet
File name:The details for your perusal.zip
Download: download sample
Signature AgentTesla
File size:533'874 bytes
First seen:2020-07-09 07:27:36 UTC
Last seen:2020-07-09 11:38:56 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:a1gxh9vYBRO6HP434QrD/xESKtCGQMjOA+UFDWEHIcKozVO5:a1uORfg3PGSrdAqlEH1KQg
TLSH C0B4237DB3F4E001612051914E2F98DEEEF6BF057B5BA5376782ADFE843092B00BA125
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.willgroup.com.my
Sending IP: 103.217.92.165
From: Santosh Shukla<sitizubaidah@willgroup.com.my>
Subject: the details for your perusal
Attachment: The details for your perusal.zip (contains "The details for your perusal.exe")

AgentTesla SMTP exfil server:
mail.emailsrvr.com:587

AgentTesla SMTP exfil email address:
zz@royale.net.in

Intelligence


File Origin
# of uploads :
2
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-09 07:29:04 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3a1869a3ad86bca973acdc80ccc9ae81735117dc0a29a584d5d1db0f8c09a1b0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments