MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b5769968f5dc452ed0f0c9b51f8c6eeb133d8c5f8520bf0e66c3f3d83d79d5b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5b5769968f5dc452ed0f0c9b51f8c6eeb133d8c5f8520bf0e66c3f3d83d79d5b
SHA3-384 hash: 407953460667cd93e2a914415424cf540a376945db1960621b21978fb30da4a34ea43700f5ec849b198e2bdf0b2d89b9
SHA1 hash: bf07cca335527fe93e2493f27d2f47029428fb86
MD5 hash: 359ee2da9579f8ce5a0c10cc608a7124
humanhash: quiet-white-solar-bravo
File name:New Order.gz
Download: download sample
Signature AgentTesla
File size:510'249 bytes
First seen:2020-07-13 11:16:52 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:oH7Ea3Bt5EmrL0/QzlIkdziHEGAibS3r7fguNP1dSDZzUhC:mEsYm8/YIkdzikGAHHguNP1dSl
TLSH 24B4233B40702E964C1005F98E1E33683E67BDD616E562C98EA193CB762F26F75D21CB
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.zdravushka.by
Sending IP: 86.57.219.10
From: Sanda Kozinda <sales@miroadrubber.com>
Subject: Re: New Order
Attachment: New Order.gz (contains "New Order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-13 11:18:10 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 5b5769968f5dc452ed0f0c9b51f8c6eeb133d8c5f8520bf0e66c3f3d83d79d5b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments