MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83ddb0a41496299c644b87568789339017e0cb7ecb4fcfb6341c41992695f1a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 83ddb0a41496299c644b87568789339017e0cb7ecb4fcfb6341c41992695f1a0
SHA3-384 hash: 1ffe012037687fc70ca31e867bbec5931690cd53a7e8a425aa64058fa394d1faeda3d22c2afe5183675d953e6ede3540
SHA1 hash: baebb0d721c2d5ac9d3cde6e8c211819bc057b57
MD5 hash: a323c55871d3041cb09342c6b1b0229e
humanhash: louisiana-georgia-salami-batman
File name:Bank Report.Doc.r09
Download: download sample
Signature AgentTesla
File size:477'881 bytes
First seen:2020-08-30 08:52:08 UTC
Last seen:Never
File type: r09
MIME type:application/x-rar
ssdeep 12288:M11Xv024hVU1phDF8JW5SGSYTWYJXeJo5KPG7ZBSA3Gb:O1f0R0EJI0YTWYRB7+SA
TLSH A2A42362FC8E51DFA0670BD135EED01D124FA11BE295363F626C06F79521E0AFBA225C
Reporter abuse_ch
Tags:AgentTesla r09


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.thebricspost.com
Sending IP: 64.15.138.14
From: ACCOUNT DEPARTMENT <info@marahotels.com>
Subject: Re: Distributing Inquiry(Top Urgent)
Attachment: Bank Report.Doc.r09 (contains "Bank Report.Doc.exe")

AgentTesla SMTP exfil server:
smtp.coffiices.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-29 13:26:37 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r09 83ddb0a41496299c644b87568789339017e0cb7ecb4fcfb6341c41992695f1a0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments