MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b1c46bcdc81631b8a19a129391e97c3552bd2a020c5a819dc1f0534db85236e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4b1c46bcdc81631b8a19a129391e97c3552bd2a020c5a819dc1f0534db85236e
SHA3-384 hash: 42be8b05985d03e3c8d1ebf5456812b600316d8761a01b5364e95606941225f165a5eabead98def0ed2aabdd18af4a19
SHA1 hash: 18f34f2a82575525f6db19e4bdd77cd84d1b7a9d
MD5 hash: a8b55c932c3257ca616538614b114b38
humanhash: mexico-item-hamper-triple
File name:SHIPPING DOCUMENTS.r00
Download: download sample
Signature AgentTesla
File size:929'244 bytes
First seen:2020-06-10 10:28:20 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:oKMTneCAi1JzkEgYrXSXceFxbZXu6QtUEQOILU/On4JvBx1:ieC3QEg8XYcmxdeDCE221Jpx1
TLSH 881533D39B90DE7F51762CBA08D9804A6F08B655FE50F5A9D1819D2A7263203C3EF1B3
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sofansteel.com
Sending IP: 95.211.208.50
From: INFO <Info@sofansteel.com>
Subject: RE: DHL Shipment Notification
Attachment: SHIPPING DOCUMENTS.r00 (contains "SHIPPING DOCUMENTS.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-10 10:30:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 4b1c46bcdc81631b8a19a129391e97c3552bd2a020c5a819dc1f0534db85236e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments