MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41a76ce46d2bbc3da3de2b41d36c5a6c7e2f204ed4c4752a51fb8dc303d87710. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 41a76ce46d2bbc3da3de2b41d36c5a6c7e2f204ed4c4752a51fb8dc303d87710
SHA3-384 hash: 3b7f392096c6c259bd437a3dc16beb1b77caafa940f9d4da4d6f54b7dd0a57c51b51a58b7157460aa66d8b71f4253c7d
SHA1 hash: 3f59b2ef5e76f2014b857b58d98797c7777aaf44
MD5 hash: eb0227a9996a8a2af41856ad3aff69be
humanhash: oven-north-kentucky-hamper
File name:Detalles del banco.rar
Download: download sample
Signature AgentTesla
File size:222'655 bytes
First seen:2020-07-09 12:16:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:PRtqVnvgNUCgI9qCUVbO1oLFmFNcJJydbwsms:PunjC1mFCmzUxV
TLSH 4F2423C15AB1C4E6345348E4F49D419E0870960A6A4DD1E073DEB98FEA7C639CB8CE7E
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: virt2877.unelink.net
Sending IP: 31.200.242.206
From: Bárbara Agudo <bagudo@sorsa.es>
Reply-To: Bárbara Agudo <info@sweraurg.com>
Subject: Re: Pagos
Attachment: Detalles del banco.rar (contains "Detalles del banco.exe")

AgentTesla SMTP exfil server:
webmail.recuperacionesbahia.es:587

AgentTesla SMTP exfil email address:
bernardkincaid01@gmail.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-09 12:18:06 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 41a76ce46d2bbc3da3de2b41d36c5a6c7e2f204ed4c4752a51fb8dc303d87710

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments