MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46f5b7d901755ceb8b5ccae590340c0ef417c4cc30f3760c24ab5374de10800b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 46f5b7d901755ceb8b5ccae590340c0ef417c4cc30f3760c24ab5374de10800b
SHA3-384 hash: b0437133e59933348c49fecadddaf575bf9879e918e957aad30df91b125ea43f9fee8f5bc54edf0651db472e2c6de4bd
SHA1 hash: 8ea6649d4b9e0dff1c6379ab307307f9d46e1bd8
MD5 hash: 9a898a1c9deb8c4e969210a172afe99c
humanhash: california-hot-gee-victor
File name:ORDER SAMPLE PRODUCTS.rar
Download: download sample
Signature AgentTesla
File size:1'232'893 bytes
First seen:2020-04-29 19:38:57 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:k0V0DDE/H6VP7cZr5JVC8agTndto9NRk28RJuXHJGB5xmZkqy:knDDE/H6VP7+FC8pAgbBUzy
TLSH E445331D112FB5B03C553ED297BCA046B223F26C6D8963650A007CDE833F6AF9B6456B
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: medvision-kw.com
Sending IP: 103.99.1.145
From: Mina Sobhy <info@medvision-kw.com>
Subject: Re: Performa Invoice
Attachment: ORDER SAMPLE PRODUCTS.rar (contains "tea.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 17:16:28 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 46f5b7d901755ceb8b5ccae590340c0ef417c4cc30f3760c24ab5374de10800b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments