MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f46b5abfef32ac4edf792d3cd692349fa62492e5c56f6eea87128faf1581758. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f46b5abfef32ac4edf792d3cd692349fa62492e5c56f6eea87128faf1581758
SHA3-384 hash: 842cc340604efed706e127d315666e7148ccfe1651d46850ca3d122c75a6a1d1b3fa0b8b5f3339bda483e25f80b74e84
SHA1 hash: 6c0a5adefab4ed9be45cdfa163291466fbf685de
MD5 hash: cdcf0bcd5b59f51c35efc77755f1b178
humanhash: two-muppet-victor-victor
File name:Payment Advice.zip
Download: download sample
Signature AgentTesla
File size:373'114 bytes
First seen:2020-06-29 06:51:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:aN9u6JFpItA9DTiQ2ceXirBfawDR8FXAnE0doioqKHoJ9MTkfdfagOq:ucPtA9/wRi1CieOE0duI3MT7gOq
TLSH A984236CF9054299C940B1C4E9EB6650092B71D466708BEF3F1FB58F073B92A4E2E9DC
Reporter abuse_ch
Tags:AgentTesla HSBC zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chieu25
Sending IP: 45.127.62.90
From: HSBC <shany@fredbaty.xyz>
Subject: Payment Advice - Advice Ref:[GLV626261062] / Priority payment / Customer Ref:[00071074502020]
Attachment: Payment Advice.zip (contains "hhh.exe")

AgentTesla SMTP exfil server:
smtp.coolwork.biz:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-06-29 06:53:06 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5f46b5abfef32ac4edf792d3cd692349fa62492e5c56f6eea87128faf1581758

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments