MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 631fd8f83508fdd432beb16fe228613d6f4db5f630c51318a324e240ab82cd36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 631fd8f83508fdd432beb16fe228613d6f4db5f630c51318a324e240ab82cd36
SHA3-384 hash: 5cba9003a4db7b6c64370b7947468502b4824ff539b4b3956f0a856826aa7d0498c3998e7cd51e2ff28ee961f3f95bf1
SHA1 hash: ecdd7c971eb32bc4001e3cae9fe522060191025d
MD5 hash: fe39dda694774940bc6e66b85bfe5649
humanhash: fix-shade-november-winter
File name:NEW ORDER.zip
Download: download sample
Signature AgentTesla
File size:460'663 bytes
First seen:2020-05-24 07:33:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:TW6lDyFRr3JQYamm2SI/KkthfjutZTtk+J1pXQ3s2vC:6Mgr3Jz4oL7u/RIa
TLSH F3A42314CB25D1A9F1D95264FCAF7F2CACE8AED93E0E96B5C40C89568D91C1C8C6DC83
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: servers.com
Sending IP: 185.234.216.137
From: Christian Zeiler<secureserver@servers.com>
Subject: NEW ORDER PRODUCT
Attachment: NEW ORDER.zip (contains "sam crpyt.exe")

AgentTesla SMTP exfil server:
mail.shrc-india.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-24 08:37:02 UTC
File Type:
Binary (Archive)
Extracted files:
316
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 631fd8f83508fdd432beb16fe228613d6f4db5f630c51318a324e240ab82cd36

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments