MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c8ee2e33138eb31e71d75cc40a0a619b720bea38da0c0d1df6684881a4f4b11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5c8ee2e33138eb31e71d75cc40a0a619b720bea38da0c0d1df6684881a4f4b11
SHA3-384 hash: ebcf55fac908f6870e526a534ea64adebdf0427a2d9f2adf5f74e13387a1143a7d9159e5a255435385d08e1291e13926
SHA1 hash: 6fa1eff421c8047cbfbd715b7f9a4f0bd5cef7ee
MD5 hash: e4f8254f869105162a9b5b0dfb15be72
humanhash: ack-burger-queen-robert
File name:Inv00911.rar
Download: download sample
Signature AgentTesla
File size:1'032'633 bytes
First seen:2020-05-13 16:27:52 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:Jy7zMjAnjo6oeflXU4YQm2mAukzHm3DG38PidLyya2iEkUxo:JyXMMnM6oilI2mAukTz38PidLiEVW
TLSH 362533C40A73074F9F66377FC73504AA89901E0D6ACAA70A2CA85A293F9056FF5F4F11
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cpanel2.cityonlinebd.net
Sending IP: 113.212.108.130
From: Accounting <qatarsales@machinecarellc.com>
Subject: Re: Swift codes of invoices 32,33,35,36 and 37]
Attachment: Inv00911.rar (contains "Inv00911.exe")

AgentTesla SMTP exfil server:
mail.chinagrill.co:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-05-14 02:59:59 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 5c8ee2e33138eb31e71d75cc40a0a619b720bea38da0c0d1df6684881a4f4b11

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments