MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80313e69f52db3939bb3bf1ab9b5d43d65034a968607d61ac2807fa0a980c53a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 80313e69f52db3939bb3bf1ab9b5d43d65034a968607d61ac2807fa0a980c53a
SHA3-384 hash: cd7dcb89c1f5fcf19dbe52b2e13f7211d7f1aae8f509fb35bdfb6f36019e433ddd3b93848fe616d010256b271a0b3319
SHA1 hash: c12f0c92465462b0c6d542660a3c79452c392ba6
MD5 hash: 6148c4c19c8fb152ed30e0b8e1ce869c
humanhash: california-item-winter-football
File name:GEA_19110069.zip
Download: download sample
Signature AgentTesla
File size:1'001'432 bytes
First seen:2020-05-26 10:32:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:9Rxi0kMu9cZnCQ3h5gQ58ZmIYov5prSnmab:9RkKu9cZFR5gQ5811v5e
TLSH F5253380B3CF861E0F55C014F3DD7B55D6C0F2B892B1208A62E11A71BAAF9BE535F15A
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pdlc34160.ciberserver.com
Sending IP: 176.221.34.160
From: Miss. Marie Palmero <opr6.ae@absaco.com>
Subject: DELIVERY ORDER
Attachment: GEA_19110069.zip (contains "GEA_19110069.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-26 10:36:48 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 80313e69f52db3939bb3bf1ab9b5d43d65034a968607d61ac2807fa0a980c53a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments