MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40b7cd8df34635365cd063467b1cd7d8c3a9ea50f2d1d02a7d1387a7d686d406. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40b7cd8df34635365cd063467b1cd7d8c3a9ea50f2d1d02a7d1387a7d686d406
SHA3-384 hash: 94e7763bddff01bcb1cb2bb112b3f029e0e7f33933482f68decf4f409900e62f139e9a20e8b91720b66d2f1deceec8d0
SHA1 hash: 6e789f6dfb843be7f341423cf37d162677e84b27
MD5 hash: a8b54156b99cf767b514f4b2e3539311
humanhash: alabama-september-arkansas-social
File name:signed_19272 2 - Copy.zip
Download: download sample
Signature AgentTesla
File size:376'715 bytes
First seen:2020-06-12 11:56:57 UTC
Last seen:2020-06-12 20:55:10 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:46GKNQA9QYYKzeKAjhcNyJm43NhVMzF0x+lW7Zh01W0wOdXil:1G/vYYKzeKJWm4936cD30Hdu
TLSH 3784239D412A9DACC0781457F592F23EB458A7FE93BC1237D6DD6CB16824C88CF21B92
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chasisautopartsengine.com
Sending IP: 103.99.1.147
From: "arnis janvars"<arnisjanvars@chasisautopartsengine.com>
Subject: RE: Signed_document for urgent_shipment 
Attachment: signed_19272 2 - Copy.zip (contains "OPO CRIPTED.exe")

AgentTesla SMTP exfil server:
mail.aneeqllc.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-12 11:58:08 UTC
AV detection:
20 of 27 (74.07%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 40b7cd8df34635365cd063467b1cd7d8c3a9ea50f2d1d02a7d1387a7d686d406

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments