MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5351ea26f369c9b979ec6989f8bacdcb41bd82bb7207279ca092dcb72c8db02f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5351ea26f369c9b979ec6989f8bacdcb41bd82bb7207279ca092dcb72c8db02f
SHA3-384 hash: f438adcab423e535a91b2354dd245a5f1b02a7cd42dc35cab996d76c56fc06b4a3376e4604b11e174020ed86285b26c2
SHA1 hash: c67a0a6a4591b411aadfa71449d67457b3a88e26
MD5 hash: 6affe8e26253127a1191c72d614d1c1f
humanhash: ceiling-delaware-asparagus-island
File name:project pdf.zip
Download: download sample
Signature AgentTesla
File size:1'028'740 bytes
First seen:2020-04-30 12:12:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:aXfv/rusM/W4qbYD7CjJ8h/DpkO7ZvDaXP4REbn:AKsV4qc/Cah/DpkKFW/UIn
TLSH 692533A2AA1491EDA70CE8A1C771BD5621F04F90B86FED75C1AB3107EF8851F16C2357
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: plateiq.com
Sending IP: 103.99.1.143
From: Maria Shayevich <maria_shayevich@plateiq.com>
Subject: Do you have any project that requires funding?
Attachment: project pdf.zip (contains "project pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-30 14:41:36 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
24 of 30 (80.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5351ea26f369c9b979ec6989f8bacdcb41bd82bb7207279ca092dcb72c8db02f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments