MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53cb84f73201c82ddd70f2b1e17cfe1bd1e929804903729183c3ec480fc4f073. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53cb84f73201c82ddd70f2b1e17cfe1bd1e929804903729183c3ec480fc4f073
SHA3-384 hash: e6e96fe7e045eb40c999193b44bf6a147576e0c831e81401781fd68feef6aa22b7de41d29ee82222de0fe6beb92f87f6
SHA1 hash: d52e650a358740e8c746dacd5d1a5cab8458bb82
MD5 hash: a39a2ce45c2833f7d70cb01b8657b93e
humanhash: eleven-music-east-paris
File name:RK- PO No- IPO-2020101.img
Download: download sample
Signature AgentTesla
File size:1'572'864 bytes
First seen:2020-06-10 11:18:27 UTC
Last seen:2020-06-10 11:18:38 UTC
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:3X1mdZML2cSAhFSt/UYc+HXtJbYVv68+N:3FeJcSWSt1cStJbWv/+
TLSH DE75BE893250B6DFC827CD7289A82C64AB60B477572BD243A44712ED9E0D7DBCF116E3
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp-7.skok.cz
Sending IP: 77.78.76.134
From: ESMA - Purchase (Orders) <import.orders@esmagroup.com>
Subject: Request for quotation: 200326 RK- PO No- IPO-2020101Dated-08/06/2020
Attachment: RK- PO No- IPO-2020101.img (contains "RK- PO No- IPO-202010.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-10 11:20:06 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 53cb84f73201c82ddd70f2b1e17cfe1bd1e929804903729183c3ec480fc4f073

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments