MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fa6a415a5d810a089310d6b0eddbb69fb3336815c49d67ddfeac364595c3147. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5fa6a415a5d810a089310d6b0eddbb69fb3336815c49d67ddfeac364595c3147
SHA3-384 hash: a5bc605878f885c86085ff41523fbbf18ffddfd34395169cf095171aac8a9376a45a87b1fd7da450df7124eb98807a5d
SHA1 hash: b9e2acf651013722beab249be47dec6568c83645
MD5 hash: 26a5005ba01a07f735302e82749e41f6
humanhash: maryland-three-september-triple
File name:case file 772020.xz
Download: download sample
Signature AgentTesla
File size:470'602 bytes
First seen:2020-07-07 10:06:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:y51ZYs/5FzY9vHWaQWVNH+XKdQ3+URqJ5:yqg5JYlWrUbdQrRm
TLSH 2BA4234E0325A1E4CEDB2C8D6086F8575FFC5675BB2166D170EA258B1F261F0C2CAB63
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cphost21.qhoster.net
Sending IP: 179.43.183.46
From: borg fritz <borg.fritz@exmarnvb.be>
Subject: RE-case file
Attachment: case file 772020.xz (contains "case file 772020.exe")

AgentTesla SMTP exfil server:
smtp.bnb-spa.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-07-07 10:08:06 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5fa6a415a5d810a089310d6b0eddbb69fb3336815c49d67ddfeac364595c3147

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments