MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fdd3e0595ce25ec72d419f2407656fec17b500c8ab43410a416f7a77375d487. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5fdd3e0595ce25ec72d419f2407656fec17b500c8ab43410a416f7a77375d487
SHA3-384 hash: b13437a21076619f00288136c16ace1044984dc9201fb2dfb223818a831fdda1985cd5f425a01fcca3a4e7757d41dfcb
SHA1 hash: fa165292e6e582df46fd4ad180ed146198bd9ffb
MD5 hash: 11e8ae2e62979f41ab70d597d5e3425a
humanhash: comet-stairway-yankee-quiet
File name:inquiry.pdf.z
Download: download sample
Signature AgentTesla
File size:408'725 bytes
First seen:2020-05-10 08:55:47 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:dNQ3HOiz8ZKnePjFzdUdZgYVJrL/hc2Kzg6:dNQ3uiADddUJNZBKzL
TLSH 5194235AACD54C641476F9073E57E2018930BD78EB22D3C6BFA207F3630A1E7F5464A6
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zimbra129-ind.megavelocity.net
Sending IP: 103.205.64.74
From: <kvnalin@amritcorp.com>
Subject: inquiry
Attachment: inquiry.pdf.z (contains "inquiry.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-10 09:35:23 UTC
File Type:
Binary (Archive)
Extracted files:
94
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 5fdd3e0595ce25ec72d419f2407656fec17b500c8ab43410a416f7a77375d487

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments