MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 83ddb0a41496299c644b87568789339017e0cb7ecb4fcfb6341c41992695f1a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 83ddb0a41496299c644b87568789339017e0cb7ecb4fcfb6341c41992695f1a0 |
|---|---|
| SHA3-384 hash: | 1ffe012037687fc70ca31e867bbec5931690cd53a7e8a425aa64058fa394d1faeda3d22c2afe5183675d953e6ede3540 |
| SHA1 hash: | baebb0d721c2d5ac9d3cde6e8c211819bc057b57 |
| MD5 hash: | a323c55871d3041cb09342c6b1b0229e |
| humanhash: | louisiana-georgia-salami-batman |
| File name: | Bank Report.Doc.r09 |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 477'881 bytes |
| First seen: | 2020-08-30 08:52:08 UTC |
| Last seen: | Never |
| File type: | r09 |
| MIME type: | application/x-rar |
| ssdeep | 12288:M11Xv024hVU1phDF8JW5SGSYTWYJXeJo5KPG7ZBSA3Gb:O1f0R0EJI0YTWYRB7+SA |
| TLSH | A2A42362FC8E51DFA0670BD135EED01D124FA11BE295363F626C06F79521E0AFBA225C |
| Reporter | |
| Tags: | AgentTesla r09 |
abuse_ch
Malspam distributing AgentTesla:HELO: server.thebricspost.com
Sending IP: 64.15.138.14
From: ACCOUNT DEPARTMENT <info@marahotels.com>
Subject: Re: Distributing Inquiry(Top Urgent)
Attachment: Bank Report.Doc.r09 (contains "Bank Report.Doc.exe")
AgentTesla SMTP exfil server:
smtp.coffiices.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-29 13:26:37 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.