MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 895cdfc8996012b26051d0c09a959b7512dcf6631736423fae6a6745b4813abd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 895cdfc8996012b26051d0c09a959b7512dcf6631736423fae6a6745b4813abd
SHA3-384 hash: 4f9075d802d9a1372eb22f952914099836270abb6bb051bf4f192e3978f2905d0ae112833cdc6b2578789a2a46974ed5
SHA1 hash: e7f20d87f3ce5e8a037199198bf2a92f52c0a72a
MD5 hash: 5243e7813b6df9608bd74cd022c3ee49
humanhash: nine-saturn-april-glucose
File name:CONFIRMATION FOR PAYMENT PROCESSING.rar
Download: download sample
Signature AgentTesla
File size:1'008'014 bytes
First seen:2020-06-08 09:14:44 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:cTqTbJ+cfLelQrrRvx6AOgcFZhPF1QbQv94P4Wa/A8x/I8P1K+:cTqp+cjoQhzYZRFf9e4WoF1K+
TLSH B925339EBE898487827B13D2431DB1C1339DE7AAD1AFFB14318CC75D6C863A47AA0355
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: joister.net
Sending IP: 103.2.236.240
From: El-basha imp. & exp. co <elbasa.adm@hotmail.com>
Reply-To: elbasa.adm@hotmail.com
Subject: CONFIRMATION FOR PAYMENT PROCESSING
Attachment: CONFIRMATION FOR PAYMENT PROCESSING.rar (contains "new 12.exe")

AgentTesla SMTP exfil server:
mail.radianthospitals.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-08 09:16:10 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 895cdfc8996012b26051d0c09a959b7512dcf6631736423fae6a6745b4813abd

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments