MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 725493d945225ad4f45a29f022efc7ba44af71615020303d8dbc75429862b9c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 725493d945225ad4f45a29f022efc7ba44af71615020303d8dbc75429862b9c7
SHA3-384 hash: 15568affef6354dd5e17555f5f9248c45e079cf66e55ddbe0e22f7fab21a2d261acd0147fea798f6949d1eca50100962
SHA1 hash: 6bee538816430e1c51ec114e4f8fccb1e90163d3
MD5 hash: b69c0149eb6024511ac12a779d3fd34d
humanhash: maryland-sink-massachusetts-mango
File name:FREE COVID-19 TEST and PPE KITS.zip
Download: download sample
Signature AgentTesla
File size:393'358 bytes
First seen:2020-04-15 17:39:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:EEe+h/YdAa7hJJ1bHPBTYD7EV+WAXNmjv:EEeHp73/H9uC+W2mT
TLSH 5B84239A06D2D92A9FE27FD2309583632ED920377DB83195082D1AC5FDA216C9F5CF0D
Reporter abuse_ch
Tags:AgentTesla COVID-19 zip


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: server0.caretrade.pw
Sending IP: 195.123.245.117
From: sales@caretrade.pw
Subject: FREE COVID-19 Test Kits/PPE kits
Attachment: FREE COVID-19 TEST and PPE KITS.zip (contains "FREE COVID-19 TEST and PPE KITS.exe")

AgentTesla SMTP exfil server:
mail.panpatmos.co.id:587 (117.102.254.26)

AgentTesla SMTP exfil email address:
origin@panpatmos.co.id

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Casdet
Status:
Malicious
First seen:
2020-04-15 18:35:37 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
19 of 30 (63.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 725493d945225ad4f45a29f022efc7ba44af71615020303d8dbc75429862b9c7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments