MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 931a11f319a2aed40238da780b2186268873d3e8eee49862db70e1b6f5114161. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 931a11f319a2aed40238da780b2186268873d3e8eee49862db70e1b6f5114161
SHA3-384 hash: 26b5287f7be2f940ea31c40c7eb05472c96fe54b15e7b43f2162194a1276afeea0caf7880616b7093ee6630bf943a5f3
SHA1 hash: 4102a61d17b7a96b72bf8c7894980d4a88cb1864
MD5 hash: 1a82915f36d709584408cbb71dac1e83
humanhash: oxygen-batman-december-east
File name:Case file.zip
Download: download sample
Signature AgentTesla
File size:425'790 bytes
First seen:2020-06-25 09:36:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:TUr3zGbpuIK4hOlOMsUkz32ApFuke0JVTRq4oC:eDGbUlOj6AfVPS4oC
TLSH 219423EC1CE5FB1D9C21A38DE8F8EF8D22A91856A8230533362F17D53114AE65DF45CA
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 37.49.224.4
From: High Court<fhc243@gmail.com>
Subject: Case file
Attachment: Case file.zip (contains "TT copy of balance payment.exe")

AgentTesla SMTP exfil server:
smtp.bnb-spa.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 931a11f319a2aed40238da780b2186268873d3e8eee49862db70e1b6f5114161

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments