MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59727f6821600215e5634cde95bfc6b6cc812e916322f9e7f8a19660c119ee1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 59727f6821600215e5634cde95bfc6b6cc812e916322f9e7f8a19660c119ee1c
SHA3-384 hash: 554961c6ff8524237f7e75d1534507e44ebe1275b9e1b622d9ba7be36ad412791b51a605bc2fe6afde7f6463a3ae4cf2
SHA1 hash: b7fad65ed1698e5dddb1707b73b4d08022636008
MD5 hash: 604db4188c86c1cc8ddfdf16f73aa268
humanhash: jig-foxtrot-pasta-maryland
File name:POLpo-1037.zip
Download: download sample
Signature AgentTesla
File size:396'899 bytes
First seen:2020-06-15 12:26:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:KpTf5nqWMbSrKs63QNqixGqWYZS/hX1sbXK1uYHWEh7cgFU+6:KlRnqWMeVbw7d6g2E1cg2
TLSH AC84238A7443246A9B91CD63A641F0E7C795637FB02B15FB80A2DE7B660714270C73C4
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hansflorine.com
Sending IP: 95.211.208.25
From: <info@hansflorine.com>
Subject: Purchase Order#Lpo-1037
Attachment: POLpo-1037.zip (contains "P.O#Lpo-1037.exe")

AgentTesla SMTP exfil server:
smtp.rezuit.pro:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-15 12:28:07 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 59727f6821600215e5634cde95bfc6b6cc812e916322f9e7f8a19660c119ee1c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments