MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a1c83d3446285b1515956cdc98bb8373d267178e1a219aabf5a9e51b50ae4f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5a1c83d3446285b1515956cdc98bb8373d267178e1a219aabf5a9e51b50ae4f2
SHA3-384 hash: 27fe3ad569eb1fb47b63f95236e6bfa1150fa63ba9a5cae669b878b6b7088c5dd199c97e42d7877e52ab72e9a903f36f
SHA1 hash: 65d6a590f1e275f1296354ef9fadaa8392533e64
MD5 hash: f81bc06a3d7c21f9e67c917a77c8139d
humanhash: alpha-hot-twelve-march
File name:Payment doc747322.zip
Download: download sample
Signature AgentTesla
File size:484'995 bytes
First seen:2020-07-13 06:33:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:w4YBTuMyOtY7+ImEY+H+kW0BKIODe2jcxDOpX:bQuMLtDfEYVNIxDKX
TLSH ECA423685CBCBD3A736E11855999D68040B3ECD4F923AB3913B5A92021DF39F439D1F8
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.miyoshi.biz
Sending IP: 111.235.136.178
From: Rini Mutia <exim6@aggoi.com>
Reply-To: exim6@aggoi.com
Subject: Re: payment (Statement Of Account July)
Attachment: Payment doc747322.zip (contains "Payment doc747322.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-13 06:35:04 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5a1c83d3446285b1515956cdc98bb8373d267178e1a219aabf5a9e51b50ae4f2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments