MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 762d163a3de6d5efab66a4a651cfab45d97a57cc4d814ab02a35f2d90db9a810. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 762d163a3de6d5efab66a4a651cfab45d97a57cc4d814ab02a35f2d90db9a810 |
|---|---|
| SHA3-384 hash: | ff416c3333d367ae9d7ca0a2ad5505d95102caf4d858dbb4a837f9453cbdf623d9c8d104e8f159331f03ad66b3542975 |
| SHA1 hash: | 8505a2a032a7db812dbb51a996a6be40ca991647 |
| MD5 hash: | 60ed5143736b6a1bd044ebb72dc4fffa |
| humanhash: | music-salami-autumn-east |
| File name: | 60,400.00 usd Outstanding Invoice.xz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 562'011 bytes |
| First seen: | 2020-08-18 19:27:20 UTC |
| Last seen: | Never |
| File type: | xz |
| MIME type: | application/x-rar |
| ssdeep | 12288:srrwZgV5sBqR4JqFZsfqGUkEe4kkJTYQ5Mhy1D:srr0KtFwfUkOkkaQmhcD |
| TLSH | EEC423FDCF364A90084AF2EF57C1E2EAE9817C50D56552EEDA2973F04297C8621C4B38 |
| Reporter | |
| Tags: | AgentTesla xz |
abuse_ch
Malspam distributing AgentTesla:HELO: zpcir.com
Sending IP: 185.222.57.207
From: Sahar Hosseinii <s.hosseinii@zpcir.com>
Subject: FW: 已读: Outstanding Invoice
Attachment: 60,400.00 usd Outstanding Invoice.xz (contains "60,400.00 usd Outstanding Invoice.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.NanoBot
Status:
Malicious
First seen:
2020-08-18 11:45:43 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.