MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59da575c89b734e66357a81507047328ba6e7e828f9ce329841c99c53d0d2324. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 59da575c89b734e66357a81507047328ba6e7e828f9ce329841c99c53d0d2324
SHA3-384 hash: f9daebc5ca6c6bd2573471cfb23be1d614aa21db211d769242aa98af00cda121c8b995af3c30c1980e3fe8800c50fdcb
SHA1 hash: a4b9080640b1d6d273d110d2b67c1080fd7fd922
MD5 hash: 97d24dde6e6c7b88effe116875a41030
humanhash: indigo-speaker-washington-whiskey
File name:Payment Copy.PDF 299KB.zip
Download: download sample
Signature AgentTesla
File size:442'181 bytes
First seen:2020-06-29 06:23:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:GNk/yNDHNmJzKtqocVqSlPNiodIByCUMe5Gusd66oB:o0yNzizKgocVbOqsyrMwGr67B
TLSH D39423CA58A1A2B64377FB92135E0707E678024CB73DD1AAB7231610BB5D0339E729DD
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.macartajans.com
Sending IP: 89.252.130.69
From: HSBC Advising Service <milesthornhill@hsbc.com>
Subject: Payment Advice - Ref: HSBC99002992/26062020
Attachment: Payment Copy.PDF 299KB.zip (contains "Payment Copy.PDF (299KB).exe")

AgentTesla SMTP exfil server:
smtp.knmbz.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Occamy
Status:
Malicious
First seen:
2020-06-29 06:25:05 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 59da575c89b734e66357a81507047328ba6e7e828f9ce329841c99c53d0d2324

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments