MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92fd598a74cc9e5504cf741b8e43eb9140034a36d75eea66cc7915361fdc3471. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92fd598a74cc9e5504cf741b8e43eb9140034a36d75eea66cc7915361fdc3471
SHA3-384 hash: cee7d637e13cb164b7f34e064a559b2b2278876f01d5a8f301ade79a778519c8854983816fb4ff5df7cd0cce872c619f
SHA1 hash: 8186de970585aecfda6c0c8d7962f79e37100948
MD5 hash: ae881fc723525ac91b6af345e29e8c92
humanhash: south-beer-edward-bacon
File name:Transferir copia 19-06-2020.7z
Download: download sample
Signature AgentTesla
File size:481'624 bytes
First seen:2020-06-19 05:47:43 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:f7hyeHOVT2a8HQBdcLF9sokpHRdC39XiV7hec8j64cl:d/OMQTxokrdcm7h4A
TLSH BCA42371ABFF5D3AD982FF480F4C87C8A72B521D0816DD60A5A6C3D69D6429C81BFB40
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.eib.ro
Sending IP: 92.55.148.78
From: Luis Carlos Aguilar <luiscarlosaguilar@gmail.com>
Subject: Transferir copia 19-06-2020
Attachment: Transferir copia 19-06-2020.7z (contains "Transferir copia 19-06-2020.exe")

AgentTesla FTP exfil server:
ftp.tde.ro:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-19 05:49:03 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 92fd598a74cc9e5504cf741b8e43eb9140034a36d75eea66cc7915361fdc3471

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments