MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 44f3cb31cb0eaececb35e3d1bdf180b088a5e09cbddfea663c564b3913433473. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 44f3cb31cb0eaececb35e3d1bdf180b088a5e09cbddfea663c564b3913433473
SHA3-384 hash: c2052f8676bb139579cbaa0a521bcea641ed807925c8785136676729b48595078ee38d7289f622b5d7a4ef3996fb6b15
SHA1 hash: c199667cc8020223e080239d4111164ab8063789
MD5 hash: 9ff0b0923dcc50147c56205bdf91bf41
humanhash: uranus-pizza-salami-avocado
File name:payroll.rar
Download: download sample
Signature AgentTesla
File size:408'940 bytes
First seen:2020-05-11 14:32:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:GmWZPJCVIJT0ejwnqIaRWOUqhmptpnXuU+vHOCLyUfNjMtaqok5Am6Lv3HY10wC:GpZxeIJ2WCtpnXn+GCLzMtaiCm640r
TLSH 01942344049BCF59B639DEF6F40F6B18C687C168991C1389EBADD0C6A8D645F43ECAC8
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sadana.dua.rumahweb.com
Sending IP: 103.253.212.215
From: Personalia <recruitment@antam.id>
Subject: PaySlipEmail
Attachment: payroll.rar (contains "payroll.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-11 14:36:59 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 44f3cb31cb0eaececb35e3d1bdf180b088a5e09cbddfea663c564b3913433473

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments