MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d6adb45b997014c84e097889740534305dc37a84a65dfd3fc0811dc9b335c78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5d6adb45b997014c84e097889740534305dc37a84a65dfd3fc0811dc9b335c78
SHA3-384 hash: 6e307547862a6f833d78966a8f553138eb5a2d4737f62621f874209e752faf8ced0e03fb6ebe70cae0a3e6a9452a6335
SHA1 hash: f294dd24e190f662438b1be4ae09cf7f4fe7bf3b
MD5 hash: 5ac2f3cfd9121969169d9d4338113bf0
humanhash: skylark-romeo-ink-quebec
File name:PURCHASE ORDER.XZ
Download: download sample
Signature AgentTesla
File size:462'234 bytes
First seen:2020-07-10 07:28:46 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 12288:+DqO6fy0Lr4HHxFe31ZFfqkUJYXEKnXl9EPRJ:4qO6jr4xiZFikUAnXHEPRJ
TLSH 22A423EA5C9525AEDDC7ACD891310E2F6C44832C61AF85B0477B09DC330B9A6778FD62
Reporter abuse_ch
Tags:AgentTesla Endurance xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 142-4-22-49.unifiedlayer.com
Sending IP: 142.4.22.49
From: ORDERS2 <orders02@instabioanalytik.com>
Reply-To: lambertchan12@gmail.com
Subject: AMENDED PURCHASE ORDER
Attachment: PURCHASE ORDER.XZ (contains "kedycript.exe")

AgentTesla SMTP exfil server:
mail.wolterfan.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-10 07:30:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

xz 5d6adb45b997014c84e097889740534305dc37a84a65dfd3fc0811dc9b335c78

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments