MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b0fe1f4cfb10e06abc3603956fcf0953de6e4ab63a034665d449b4f880366ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6b0fe1f4cfb10e06abc3603956fcf0953de6e4ab63a034665d449b4f880366ef
SHA3-384 hash: ed5b775630a849b62bb8a75cc0c4615c0e40265babefe7dd9a898ad07c50cc9f6f26fe0a961f37c61997a3da417fa9e8
SHA1 hash: 72b02f669454dffe97723340b19d020c1aaf19e9
MD5 hash: 3668fc5c56b2a376e8cefb0171ea15e2
humanhash: april-zebra-angel-south
File name:Purchase Order - 8279018110.zip
Download: download sample
Signature AgentTesla
File size:333'091 bytes
First seen:2020-06-10 11:37:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:mJglnMqy9RRq8OSTmyehQ23JWQqKrfouhKIY6f62GCUVZMkGjCDPB9q35IjVioWA:myY9RROe23JL2TmUHMk7DPSqxioD5
TLSH 7A6423201E7EF237E07F34FB564115E678183173082845BEE3E285D4A96DA3C89A3B76
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: WIN-5N32IZXJST4
Sending IP: 103.138.109.162
From: Letain Chen <LetainChen@gmail.com>
Reply-To: s-cassidy@inbox.ru
Subject: Purchase Order - 8279018110
Attachment: Purchase Order - 8279018110.zip (contains "Purchase Order - 8279018110.exe")

AgentTesla C2:
http://farda-oil.ir/wp-includes/Text/lki/ori/inc/1f68ac5278bd3f.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-10 11:39:04 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 6b0fe1f4cfb10e06abc3603956fcf0953de6e4ab63a034665d449b4f880366ef

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments