MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c238af0150dca6414fb341cfa7cb9f3dfedb34af409f6dd757d7b6603828979. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3c238af0150dca6414fb341cfa7cb9f3dfedb34af409f6dd757d7b6603828979
SHA3-384 hash: 4caa663c889a137142f861e4064fa65fbff408da7bfbd13c26cedf5cf13a46ef1947cced44b3ce4ce23bdf5d1152b2dc
SHA1 hash: d92e4226ec911bd90459a20054d4f3c652f32f96
MD5 hash: 236151e8c2c89add19e9214e8a992982
humanhash: stairway-asparagus-butter-indigo
File name:paymentMT103-0000002.rar
Download: download sample
Signature AgentTesla
File size:971'250 bytes
First seen:2020-05-13 06:27:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:pUmeIv6I+sJmXrPR2KN5ETKao0gkrpmK1DRqu9DFMQ:6IvT+s4rwKN5t0gatRqutFMQ
TLSH 02253356304E872B5102B685F7CDDE1B4AE50012F8A0DAFA6AD7E3C1CC8F4969F11BD9
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: winpro1.internet-webhosting.com
Sending IP: 103.8.24.77
From: <hr@megamart.com.my>
Subject: PaymentMT103-0000002
Attachment: paymentMT103-0000002.rar (contains "paymentMT103-0000002.exe")

AgentTesla SMTP exfil server:
mail.temboventures.co.ke:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 06:36:55 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3c238af0150dca6414fb341cfa7cb9f3dfedb34af409f6dd757d7b6603828979

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments