MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 531cc80fd2012214be2676f3ec2358989ca6464308332c6470b73c70996b8ba9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 531cc80fd2012214be2676f3ec2358989ca6464308332c6470b73c70996b8ba9
SHA3-384 hash: 6878a58e5c0f9036aea558344bc0596d4df1bf6767d2ae5eeb6891db36d69dc03346d4a249663bd2410af306ff924829
SHA1 hash: d5a60abad20dad6695f2fe000df09896c2650be6
MD5 hash: 6bc821c13425d82c838aae672056a30b
humanhash: july-batman-four-hawaii
File name:Alibaba-Enquiriess_new-ord-Pdf.gz
Download: download sample
Signature AgentTesla
File size:515'134 bytes
First seen:2020-07-29 05:25:45 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:lqYyqBjysHF/J9cvOOCKNk29hqJxl8hHGTN6WIcK+sOiisuU+IfgTC7Xg1h2sRhU:UEBjyWR9cvqYwpVIcH8/CTSXg1rPif
TLSH 93B423785ACE11DB7C32579EB9832DA2C0583D9D1102548CFE605EE5936AACF8C7EDB0
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: arteform.co.uk
Sending IP: 155.94.185.79
From: Alibaba <info@arteform.co.uk>
Subject: (You have a new enquiry) Reply: Re: Mask-N96- Quantity-1m------USA.-SYD-D9768
Attachment: Alibaba-Enquiriess_new-ord-Pdf.gz (contains "Alibaba-Enquiriess_new-ord-Pdf.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-29 05:27:07 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 531cc80fd2012214be2676f3ec2358989ca6464308332c6470b73c70996b8ba9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments