MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 575e4722e557e333d3323dd47da723b0023ba1f57fcb13e3dbee30be51b70c51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 575e4722e557e333d3323dd47da723b0023ba1f57fcb13e3dbee30be51b70c51
SHA3-384 hash: 71c786c73dd714057e819c0be1e1f928274562e8f00151f00c74c3e6b8fab1ea7ced15493a90215ede132579e28ba852
SHA1 hash: 47f7a12bd5578d061c9baf8fe485d455ecdcf245
MD5 hash: 94e0c125382d730c6044554130ef6ef5
humanhash: autumn-failed-cold-ack
File name:Payment Advice 00575894.r00
Download: download sample
Signature AgentTesla
File size:233'532 bytes
First seen:2020-06-23 17:19:58 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:J8x+LFswtM0VheiKRlOe9fZDfYUic7e63RwmV3ToM/TWXay+kXLi8PRDj:J2qNM0dKRl9fVQTcqApVjx/TCT7DRP
TLSH B0342357DB29FF38B027AA9ED829F3951D53B2A31D30532D16800654DE0D3E8AEFE251
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: urbacon-intl.com
Sending IP: 103.207.39.104
From: "Caroline Ohanna" <r.tulagan@urbacon-intl.com>
Subject: Payment Advice - Advice Ref:[GLV622041100] / Priority payment / Customer Ref:[802448
Attachment: Payment Advice 00575894.r00 (contains "Payment Advice 00575894.exe")

AgentTesla SMTP exfil server:
mail.wasstech.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-23 17:21:04 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 575e4722e557e333d3323dd47da723b0023ba1f57fcb13e3dbee30be51b70c51

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments