MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 815a92c5c1f1e4d9cf71f49cd8604ac3dfc519a02bce01a1c9ffd1b6fbb337fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 815a92c5c1f1e4d9cf71f49cd8604ac3dfc519a02bce01a1c9ffd1b6fbb337fb
SHA3-384 hash: 84e400af3b887ee448ad88dcb025de44780b294f1e827d1b576ccc58bc70d6039ba6fbc436079148ee92d13bdc701a8b
SHA1 hash: d3074842002036804e9ae61f67db16e543263196
MD5 hash: 9198517427d251e36413fb57c7ec7861
humanhash: maine-uniform-undress-stream
File name:Doc 393618521430.gz
Download: download sample
Signature AgentTesla
File size:392'416 bytes
First seen:2020-07-16 08:55:56 UTC
Last seen:2020-07-17 13:04:35 UTC
File type: gz
MIME type:application/x-rar
ssdeep 6144:aLr1QF2RB15a7xlW/DsY/ImLjm9zGEGYn+NmSK0Zy5QAhnWkbo3jIb+BRJ7qenkf:+InusY/ImG8GO5ZQQmnejkaRJOen4+Yh
TLSH 068423D36492CDF84836D6B38BD727119DF7233686B7C627676B8902631F31C6A90293
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pipehangers.in
Sending IP: 95.211.211.232
From: contracts <contracts@pipehangers.in>
Subject: New Doc original shipping documents
Attachment: Doc 393618521430.gz (contains "Doc 393618521430.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 08:57:04 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 815a92c5c1f1e4d9cf71f49cd8604ac3dfc519a02bce01a1c9ffd1b6fbb337fb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments