MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9227ca11ea56eca7fba8a3489999d212e38b71be5ee7d689c05ed00eabdc9f12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9227ca11ea56eca7fba8a3489999d212e38b71be5ee7d689c05ed00eabdc9f12
SHA3-384 hash: fbd75a7083d236516a29fa2a15560045f876aa141e19b1c7816455faf9b300d31a6e577e7643ff3412c6880d5a2588bb
SHA1 hash: 894d465ce7feaf080dd148ecf9b96b12da8a8a2a
MD5 hash: 411551ba7053ea340522cfe24f6b4773
humanhash: network-leopard-failed-robert
File name:INQUIRY ORDER.gz
Download: download sample
Signature AgentTesla
File size:514'948 bytes
First seen:2020-08-18 06:24:24 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:XTmmZIas3aT0mfPZy5yRAcFKP/O6zxJmBSE2EN:XT6aT0k052AcFW/Oax1Xm
TLSH A8B423C674C4879047E170E5F0EEFEE09EACBF23408FE6CA0D46144649668AE99F2F01
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.agroup.cf
Sending IP: 173.82.245.245
From: MS ATIKAH <info@agroup.cf >
Reply-To: kelveneric88@gmail.com
Subject: MULTI-IMPACT/INQUIRY ORDER
Attachment: INQUIRY ORDER.gz (contains "INQUIRY ORDER.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-17 13:10:58 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 9227ca11ea56eca7fba8a3489999d212e38b71be5ee7d689c05ed00eabdc9f12

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments