MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 906786dda4d680bb24ac318d8a808c3c88a46f878cabebabb3141d8b189a50e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 906786dda4d680bb24ac318d8a808c3c88a46f878cabebabb3141d8b189a50e8
SHA3-384 hash: e80d08b5da0057faedf79a7f26aaa35947b2a3e4db0e49335f5bef70308eadc59dcd355d200d532baa1210d7bac7d2a4
SHA1 hash: ea2441c02cb089f3342a4e28142249e4e8558b43
MD5 hash: 9f8cc1b0e4e12feace26fa09730a8502
humanhash: uncle-missouri-oklahoma-asparagus
File name:Pictures,Invoices,5x40ft Containers.z
Download: download sample
Signature AgentTesla
File size:775'409 bytes
First seen:2020-06-20 06:55:21 UTC
Last seen:2020-06-20 06:56:32 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:ND+lSC7UkDYe3h/PYTRkqjtogG6djBJl7q7O/28cgNZM/veebgrvfBsG85+Izfwq:yds06kqjtcYt6qTHM/vCiOCfwcw7WF
TLSH 1FF4230B01BE602A3CA5D9365BAB4B35878C4407846EEB11537E7DBB8F556B363E3036
Reporter abuse_ch
Tags:AgentTesla Yahoo z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic313-10.consmr.mail.ne1.yahoo.com
Sending IP: 66.163.185.33
From: Amber <pratik.hakim@yahoo.com>
Reply-To: brentdamantel@gmail.com
Subject: Ready For Shipment
Attachment: Pictures,Invoices,5x40ft Containers.z (contains "Invoice.exe")

AgentTesla SMTP exfil server:
smtp.privateemail.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2020-06-20 06:57:04 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 906786dda4d680bb24ac318d8a808c3c88a46f878cabebabb3141d8b189a50e8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments