MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40dcc00013462e0f250a3315ba5597ad2dec9e6dbe75a0c0befe4ad98fb9ed28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40dcc00013462e0f250a3315ba5597ad2dec9e6dbe75a0c0befe4ad98fb9ed28
SHA3-384 hash: ee46e034581ec9c247980a6bb4a2e176ce4d095dae5196238a0d9953ff72b6292b7dea70f85777f0a8651aa88476c9db
SHA1 hash: 6b2276ec972a1fc6ebe4b9e12cdda7b602299bec
MD5 hash: 1963894d275c13a6a238c7e23f2f298f
humanhash: cola-tennis-network-cardinal
File name:345543455434543_pdf.gz
Download: download sample
Signature AgentTesla
File size:375'777 bytes
First seen:2020-06-15 05:33:50 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:lss9thPQbQZl2zUv3PEANkcwJ66s/QwiExuLPOiNkLVo2t5ACSHZNv8i:WsrhPSQj2zSEAOjJ6MExyPLGZo2t5rST
TLSH 4B84222C51009471BA8965AFAD2F9FF3335B3175A314BC6E958CFCB74A370B1A18A171
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cofradias.altia.es
Sending IP: 176.58.12.79
From: Remei Gomez <r.gomez@hyva.com>
Subject: CORTE DE JUSTICIA (ORDEN JUDICIAL).
Attachment: 345543455434543_pdf.gz (contains "345543455434543_pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-15 05:35:09 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 40dcc00013462e0f250a3315ba5597ad2dec9e6dbe75a0c0befe4ad98fb9ed28

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments