MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 755dc384c4d70c974aec6751d09f976b4b9195d068480d636e50c526cb10369b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 755dc384c4d70c974aec6751d09f976b4b9195d068480d636e50c526cb10369b
SHA3-384 hash: 687fe75be99aa090834a5b20b7915202e72c7e8da7fcb307e6086ee487e50893bdde3859c2cfb920146df64c0b1d05d4
SHA1 hash: 8e2b35fcc24ada2faa9716443fa538c34996da52
MD5 hash: ebf18bb7595977672394b0d0e2812858
humanhash: uniform-cat-speaker-papa
File name:NEW ORDERS.rar
Download: download sample
Signature AgentTesla
File size:927'388 bytes
First seen:2020-06-02 17:13:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:aVmrHTJUvt9cbCJk18B/1GXLBUwlRD9i3aAj4:a0HdUyCG8B/1UBUcbih4
TLSH 4C1533DBAED905AA03A93A73D3FBCAF87BD0C75179D9A40380BC69B3CD2D3655119420
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: formosatex.com
Sending IP: 103.147.184.73
From: mithu@formosatex.com
Reply-To: mithu@formosatex.com
Subject: Re: NEW ORDER
Attachment: NEW ORDERS.rar (contains "NEW ORDERS.exe")

AgentTesla SMTP exfil server:
mail.radianthospitals.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-06-02 17:36:42 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 755dc384c4d70c974aec6751d09f976b4b9195d068480d636e50c526cb10369b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments