MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d99699e4c96c2925da5fc64d2e935f675479edde943a926945af7de15cb4dd7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5d99699e4c96c2925da5fc64d2e935f675479edde943a926945af7de15cb4dd7
SHA3-384 hash: 820d455dee8313340dfe67fc2844de1975433addaeb23bbc0f3fe1caa9525c91e3cbf1b55132d087c3fe2f19ffd829c5
SHA1 hash: b0bcda10ef54a0ee9a42f46b350280ad8283c9ce
MD5 hash: 81e53a3d9b17e8c6c525416ebc587bf1
humanhash: river-neptune-glucose-oklahoma
File name:FedExi jälgimisandmed-pdf.7z
Download: download sample
Signature AgentTesla
File size:240'541 bytes
First seen:2020-06-29 08:56:53 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:hchbVsQyy0Wiiq/GFcDcxJWd4xTFzh68XNZn8v4tIfiOjwgxaB:habV9MWkeFg1d4x9hhXji4tITs4I
TLSH 163423960BFFC1BCD8A2190C3F5EB38691D20DA0C1D9AB12C9D5FA6723A77C56404ED6
Reporter abuse_ch
Tags:7z AgentTesla geo GRC


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: linux1187.grserver.gr
Sending IP: 95.216.14.228
From: Stefanie Schmidt <Stefanie.Schmidt@boeschbodenspies.com>
Reply-To: Stefanie Schmidt <dustiutd12@hotmail.com>
Subject: ΑΠΟΔΕΙΞΗ ΠΛΗΡΩΜΗΣ
Attachment: FedExi jälgimisandmed-pdf.7z (contains "FedExi jälgimisandmed-pdf.exe")

AgentTesla FTP exfil server:
ftp.kassohome.com.tr:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Azorult
Status:
Malicious
First seen:
2020-06-29 08:58:06 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5d99699e4c96c2925da5fc64d2e935f675479edde943a926945af7de15cb4dd7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments