MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 580bb55f65794a7c10c80501d6f4e3f00749218fdfcbd193371a70cbab2505b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 580bb55f65794a7c10c80501d6f4e3f00749218fdfcbd193371a70cbab2505b8
SHA3-384 hash: 25706defec89b9654c59fcf882293d22e4e2fa5a29d19d995e5ae95354c0d88222e4f70a0f12cb1798f80ad6f47b895b
SHA1 hash: 0eb8c16b94f38b00d114137584a68811197be051
MD5 hash: da49063f027ce527ce37b964de634ce8
humanhash: moon-victor-queen-orange
File name:Gasket-11 may 2020-PDF.zip
Download: download sample
Signature AgentTesla
File size:423'125 bytes
First seen:2020-05-11 08:58:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:hSTGTV5rCGbNtwiv6sDKzS3IKE7BsXSsHnGBG6x:bTHthVC8/ID76zn6x
TLSH 3C94239903D81C66E576D6D46E4A7523ACB62401F24E3CF9FA9CA5C040CEC2F8E5E537
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: a2nlsmtp01-03.prod.iad2.secureserver.net
Sending IP: 198.71.225.37
From: sh.kazemi <info@maneschi.com>
Reply-To: onye.oma50@mail.com
Subject: ANHAR-MOBIN-Gasket-INQUIRY-10052020
Attachment: Gasket-11 may 2020-PDF.zip (contains "Gasket-11 may 2020-PDF.exe")

AgentTesla SMTP exfil server:
mederfashion.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Rdn
Status:
Malicious
First seen:
2020-05-11 09:36:27 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 580bb55f65794a7c10c80501d6f4e3f00749218fdfcbd193371a70cbab2505b8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments