MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7c1ef6bd089a020d4cd4c37055944ad407afd55f111317c28d3107a61eaf6767. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7c1ef6bd089a020d4cd4c37055944ad407afd55f111317c28d3107a61eaf6767
SHA3-384 hash: 2c22472e4aed185614d4bd2f8af3cb71af441352a59f21209bf9f1c6c2a2dd125459938820c04e0fb39875ba4915c263
SHA1 hash: f067cdf34ecd6555be7df990105eff30dd5e233b
MD5 hash: 723cba7bdab156d0e57832940ad8cba0
humanhash: purple-lactose-william-paris
File name:new-order.xz
Download: download sample
Signature AgentTesla
File size:973'623 bytes
First seen:2020-05-13 06:02:36 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 24576:mrnEkQZ4T/pFpG/SpFlgrMUl637EBQ3g6h5Lotso+WlCB:unEk/dxB17EIv3LQsUlCB
TLSH 1A2533DC8EAF2E0E574E0B114966500A82369D3932C3E58738B25627DC4D8AE654DEFF
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: winpro1.internet-webhosting.com
Sending IP: 103.8.24.77
From: <hr@megamart.com.my>
Subject: FW: URGENT NEW ORDER.
Attachment: new-order.xz (contains "new-order.exe")

AgentTesla SMTP exfil server:
mail.elsewedyindustrial.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 16:03:54 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

xz 7c1ef6bd089a020d4cd4c37055944ad407afd55f111317c28d3107a61eaf6767

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments