MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f499a63e11a9380f0264c196992bfe9a0e78e2eee74f4418e4f520d4cd356b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3f499a63e11a9380f0264c196992bfe9a0e78e2eee74f4418e4f520d4cd356b3
SHA3-384 hash: 38ee20ba5f20c2a654991ec576098e129b449fc786cfcaa8fff725e8db1b1b7a1350a97114b0ebb79f55eac5239f08e8
SHA1 hash: defd0e9ba5211927078903ad0009cc3b383d2792
MD5 hash: 1fb2390d2086d474d2b5049169a95c72
humanhash: island-cup-six-two
File name:Invoice.r00
Download: download sample
Signature AgentTesla
File size:661'395 bytes
First seen:2020-07-20 08:00:25 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:TrBEhW/cqb2zFlohGsU0Cl24CQgaN+oPGkAIHEHEPmK1JfllTEBZJ60J7Pc4vO5a:TtEhW/cqazF+hn7YQaN+oOkAIt1J9FA1
TLSH 57E423A67E8C47007FB49C18A4B2C303014276F5F4917B3C4A91EB2AF961D3F5AB2E59
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ssd.alsaif.biz
Sending IP: 174.127.70.180
From: MULTITECH SERVICES <exports@multitechservices.in>
Subject: RE:COA FOR APPROVAL
Attachment: Invoice.r00 (contains "Invoice.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-20 08:02:06 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 3f499a63e11a9380f0264c196992bfe9a0e78e2eee74f4418e4f520d4cd356b3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments