MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7eb0ecef3a264c7a8414f4b11130d5ad29f0518634abed56b90dace9a9777dee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7eb0ecef3a264c7a8414f4b11130d5ad29f0518634abed56b90dace9a9777dee
SHA3-384 hash: 81e893ff23ff297fde86f2bd92ce4346b07934745d0cc0bbcfa167e070dfdd15bb124e9ebcd277388d1a5645b8d5904f
SHA1 hash: fbb33fcfa5cc0c6e9fe0a4942315e019ef5a9a19
MD5 hash: eff0df548d1aad37047bf872e69311aa
humanhash: uniform-mirror-colorado-romeo
File name:BL-MAERSK ITE.zip
Download: download sample
Signature AgentTesla
File size:1'291'611 bytes
First seen:2020-04-30 06:08:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:lW08F/ssZq5V0O5Ib+HyuzWbMRhe5e54b5Annt/MC29sgVevj45qg/:KsJ5yYIbBuunMnnt72feL45L/
TLSH 9855338B0E51A7BDAE35E253592A0104E2D322EDE05D3D9A3CAD7B0232E8207DFD57D5
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: platinship.net
Sending IP: 104.37.172.27
From: OPERATION PLATINSHIP <operation@platinship.net>
Subject: AGENCY APPOINTMENT;
Attachment: BL-MAERSK ITE.zip (contains "good (1).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 16:35:22 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 7eb0ecef3a264c7a8414f4b11130d5ad29f0518634abed56b90dace9a9777dee

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments