MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77288a19a49c075347d32f4e1390d05ddde755f57475a0b7e1c7f34867911ff8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 77288a19a49c075347d32f4e1390d05ddde755f57475a0b7e1c7f34867911ff8
SHA3-384 hash: e45998c1bc82cc2c5ee669146f5f672a90966067ff9d6df330c9d54b26f8e457eb4a09a6ed6c5a76a12fec6d288c6e6e
SHA1 hash: e581e7952f77a618ecf59cf94c3d91b385f88313
MD5 hash: 383b469fd8d2d53a565a5786860549e4
humanhash: nuts-xray-mirror-mirror
File name:TC190627C.cab
Download: download sample
Signature AgentTesla
File size:412'510 bytes
First seen:2020-05-08 07:47:16 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:ZqmTeki/JTeUwbro9aXZWsQ7KhQuYF+7RWG6:cmCkUJc4ajQWWua9
TLSH 4A94237F32D8266C406056EA5CE76F74910274A8B85C123E87EB361275377F49782F87
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gateway31.websitewelcome.com
Sending IP: 192.185.143.43
From: Gloria Zegarra <j-moncada@watts-pe.com>
Subject: RE: ORDER & INVOICE
Attachment: TC190627C.cab (contains "TC190627C.exe")

AgentTesla SMTP exfil server:
smtp.gfaqrochem.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Autorun
Status:
Malicious
First seen:
2020-05-08 08:36:10 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 77288a19a49c075347d32f4e1390d05ddde755f57475a0b7e1c7f34867911ff8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments