MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 44ef5a62b6a9c014ef9e13bb699b162ad599033040f0e59c89abb119da0c10b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 44ef5a62b6a9c014ef9e13bb699b162ad599033040f0e59c89abb119da0c10b0
SHA3-384 hash: 996948223f83efa4ae2676ca9e90890e263ffe4e5b7536c6ed391774be02c5cde09d3eb163ce94a9a12fa780cf770587
SHA1 hash: 37383b1b046cddc654d030e39b4c43518f4fb177
MD5 hash: 9395d233d9c3387acdce89239696e962
humanhash: hamper-blossom-queen-yankee
File name:Product_vershold_offersheet__sample_v1.zip
Download: download sample
Signature AgentTesla
File size:425'232 bytes
First seen:2020-06-15 13:47:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:UeVMWSL5m1TI2c9mEwW1+knaTJS06iire2fGSPRtzn5l8r0oq:9VMWrk26mJh6OoHtlY0F
TLSH FB94236C41F61B03E92D2D98B729583122E696BD15408F072E58D7E217B25FDFAFC384
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: voguecuisine.com
Sending IP: 192.227.246.82
From: David <inquiry@voguecuisine.com>
Subject: RE: Reply: RE : Re-sending Order
Attachment: Product_vershold_offersheet__sample_v1.zip (contains "Product_vershold_offersheet__sample_v1.exe")

AgentTesla SMTP exfil server:
mail.almushrefcoop.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-15 07:06:13 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 44ef5a62b6a9c014ef9e13bb699b162ad599033040f0e59c89abb119da0c10b0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments