MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8690aab3bd2e7094664601bbf739c93e163c7ece800b977e117d6cf7cc10a0d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8690aab3bd2e7094664601bbf739c93e163c7ece800b977e117d6cf7cc10a0d6
SHA3-384 hash: b10a55808f7e73bd4b777989fe3b7c55380d48a31fa16f299105eb47a5a15fcd7da71188d7f670dabf1cc0f5d3696f88
SHA1 hash: c07fa525a57830010a2baf970091c356b25d1248
MD5 hash: 045d5f812beb60e7e972da7859f54371
humanhash: leopard-oklahoma-wisconsin-high
File name:Order.zip
Download: download sample
Signature AgentTesla
File size:402'206 bytes
First seen:2020-06-18 06:27:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:+EkyQFiBV+GWEKkKfdpRKDwKrJFlpKs3GZHS/1Q2zsDjZ677Nb:+LxA6Vp9GFHXGHSpsD6
TLSH B984231C95A4147ECDB848F133ADD871BC8BCA35D2118FDFB85A336881CCFA8A56E558
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: franceloc.fr
Sending IP: 45.11.19.59
From: Patrick Fac<bastide@franceloc.fr>
Subject: Order
Attachment: Order.zip (contains "Order.exe")

AgentTesla SMTP exfil server:
smtp.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.BitStealer
Status:
Malicious
First seen:
2020-06-18 06:29:05 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 8690aab3bd2e7094664601bbf739c93e163c7ece800b977e117d6cf7cc10a0d6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments