MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83d78aa86ace8c2cc6bf0bfab8f61ec4a41fe2c4b67831e452b4acf590018a3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 83d78aa86ace8c2cc6bf0bfab8f61ec4a41fe2c4b67831e452b4acf590018a3a
SHA3-384 hash: 0ef8e5ecc3b7307dd88bfee9c69859b915a49888ca662ab99221f63fa46f16891d8d6b221e03020c893dec0a98367319
SHA1 hash: dcb5bfae7cd3769d657dc8c597df0a0d7747ac92
MD5 hash: 7037ddc7b5eba5af6c4f31a2ee3e95f5
humanhash: king-burger-massachusetts-north
File name:PO_Aero_ supplies_Systems_Engineering_Pte_Ltd.rar
Download: download sample
Signature AgentTesla
File size:409'824 bytes
First seen:2020-08-08 08:07:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:sfF8ke3wOjXuGx8yAPhRDttXigjiq/thP+z5uSeB:AFgwWa1RDegj/2z5aB
TLSH 329423579F1DF9A57CBF51C8A34BB9FEA92AF96C2445EC7281C978105B25E0FA180202
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: scorpio.atomiclayer.com
Sending IP: 96.125.179.170
From: Vincent- Export Project Manager <assesin@singnet.com.sg>
Reply-To: evanesultanedeseba@gmail.com
Subject: Quotation
Attachment: PO_Aero_ supplies_Systems_Engineering_Pte_Ltd.rar (contains "PO_Aero_ supplies_Systems_Engineering_Pte_Ltd.exe")

AgentTesla SMTP exfil server:
mail.kohinoorribbon.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-08-08 08:09:05 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 83d78aa86ace8c2cc6bf0bfab8f61ec4a41fe2c4b67831e452b4acf590018a3a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments