MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e810439f40659804da8f2940759ac6fd280869fb30e6ed37d251a92a34635ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5e810439f40659804da8f2940759ac6fd280869fb30e6ed37d251a92a34635ed
SHA3-384 hash: 39c1f2b75f3329095af1809195b93d42700c998417db3ef794e04a02c8f5f7d32664a85c5e89b90b98db7236fd4ff695
SHA1 hash: e95ed10108ddbeb90ef08f94ff60b0a654e69c1a
MD5 hash: 87b9a86096de63c817f51a5dcfbc5397
humanhash: sixteen-california-football-victor
File name:COVID-19 Prevention.zip
Download: download sample
Signature AgentTesla
File size:1'170'443 bytes
First seen:2020-04-16 12:01:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:DNh/XtihTiWii0ljkB7LmxeGB9ajgj57j2wRag7nbKFMt:D7/Xtyii0jom8Kgjgj57FEgCFG
TLSH 7F453377915BE11BD49268C05ED0E638CCFA4AFE5503EBB19C19443A8DDFFC6A21A324
Reporter abuse_ch
Tags:AgenTesla AgentTesla COVID-19 zip


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: srv40.creattiva.cl
Sending IP: 200.35.157.40
From: Covid-19 Sanidad <newsletter@health.com>
Subject: COVID-19 Prevention and guidelines..
Attachment: COVID-19 Prevention.zip (contains "COVID-19 Prevention.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Aitinject
Status:
Malicious
First seen:
2020-04-16 12:35:25 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
26 of 47 (55.32%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5e810439f40659804da8f2940759ac6fd280869fb30e6ed37d251a92a34635ed

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments