MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72b9e15cdbc1ee01f2ec070561a69874ef859f322f7a5ba6c063f11be2955013. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 72b9e15cdbc1ee01f2ec070561a69874ef859f322f7a5ba6c063f11be2955013
SHA3-384 hash: 1486bd939039f6afb166c232ef40740a2d381bc261fe03061db550467b4f9303fa65fedbdd537df9fe8b3e215e842d83
SHA1 hash: 398ca04c354219a5e38ab45100228f3ec88efa55
MD5 hash: f2bbe8a66361fab38bd2049ef50e5c30
humanhash: march-earth-kansas-louisiana
File name:PCO200214-0030-0001147094_pdf.gz
Download: download sample
Signature AgentTesla
File size:345'291 bytes
First seen:2020-07-02 07:00:50 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:AqVesLr/nm53GiJhe9HyWA3bbNE3uXo/SBjbA0YzJySEZJ87Qj6CN2E:AqVesLTAu9HypX+yVZJD+Mx
TLSH 1F7423B0A275F5CD97E4903584C683F69AC78A4F39867D70DA7CD72C720096CA222F65
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hwsrv-740601.hostwindsdns.com
Sending IP: 104.168.165.92
From: Account Payable <zeco@slokltd.us>
Reply-To: Account Payable <pc.andnig.tvv@gmail.com>
Subject: RE:Revised Proforma Invoice
Attachment: PCO200214-0030-0001147094_pdf.gz (contains "PCO200214-0030-0001147094_pdf.exe")

AgentTesla SMTP exfil server:
smtp.anding-tw.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-02 07:02:13 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 72b9e15cdbc1ee01f2ec070561a69874ef859f322f7a5ba6c063f11be2955013

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments