MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 887ad0822eb765d280f5464fa6692c2422aacb7d5eae072df62a5cd84c0a1efb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 887ad0822eb765d280f5464fa6692c2422aacb7d5eae072df62a5cd84c0a1efb
SHA3-384 hash: 40ca431622d2dc1206ae4752b007d7a18faa8cb86322e2d283b9198196b7354da496b7bfde5317b06dd040804ee28a51
SHA1 hash: 10c6a891a0f4abbf9769e74427430fc244b1dca4
MD5 hash: 2fb83d3a4d7bd418f38f4fc48b58bc67
humanhash: missouri-robin-two-xray
File name:Order inquiry.zip
Download: download sample
Signature AgentTesla
File size:399'649 bytes
First seen:2020-06-24 08:28:01 UTC
Last seen:2020-06-24 10:21:27 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:inEzscT8HY8i+4nMDuNkCjfrMvp7Uk163BZslk:i+scqW+iA163Dslk
TLSH 878423C8048BC569233D13F86B94C024FCFC6699B27D8538D96E542ED043A6EB6BDF19
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: host2.himbimarket.com
Sending IP: 72.52.244.66
From: Rodrigo Peralta <rperalta@llorente.cl>
Subject: Fwd: Re: Re: Re: Re: Re: Re: order
Attachment: Order inquiry.zip (contains "Order inquiry.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
3
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-06-24 08:29:05 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 887ad0822eb765d280f5464fa6692c2422aacb7d5eae072df62a5cd84c0a1efb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments