MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60210ec6a18dd870de0d3b835e349c21b3e50cdcaed78595eb2e771b22c4daf9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 60210ec6a18dd870de0d3b835e349c21b3e50cdcaed78595eb2e771b22c4daf9
SHA3-384 hash: 356a6c5f9788c342957a6b9acbe4d23b02843d3985188ba0164f98b15d43e827f484fd2f29527371af23012ee3296db9
SHA1 hash: ef27b29f197f421c9c41e6f767adab8ed732bf47
MD5 hash: 5b425fe7513881383f2a029ff312624c
humanhash: august-romeo-violet-juliet
File name:20STMT_2021084411_YONG WANGpdf.zip
Download: download sample
Signature AgentTesla
File size:598'425 bytes
First seen:2020-08-27 05:42:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Y4Yah9spJ8IEKcB+BMUMxkA0RhW0spJwDZ8aT3gXxJnWrbFYWbV:RYvJ81BgMUMxRuWZniHgXxJn8bFD
TLSH 6FD4234AAF4B198496D4252A797FB78832F1C32177D5C80CEF0D61298ED86D4EF0D923
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.dsecargo.com
Sending IP: 203.242.142.129
From: victim-domain Davy Mao <admin@acct-recon.com>
Subject: RE: Upto AUGUST 2020_STATEMENT / MV. YONG WANG DA 17
Attachment: 20STMT_2021084411_YONG WANGpdf.zip (contains "20STMT_2021084411_YONG WANGpdf.exe")

AgentTesla SMTP exfil server:
mail.vision-architects.net:587

AgentTesla SMTP exfil email address:
hisham.metwally@vision-architects.net

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-27 05:44:06 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 60210ec6a18dd870de0d3b835e349c21b3e50cdcaed78595eb2e771b22c4daf9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments