MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 960cb20824a37a302d5741fc9d62e89852a3b9fe33a70f08ef136cc60def4705. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 960cb20824a37a302d5741fc9d62e89852a3b9fe33a70f08ef136cc60def4705
SHA3-384 hash: 2494c4884b44a73f82a4909141fc33d777a70c1cf84281366bb87f2bf1b145bf83da2f4b06f5b9c2ea3d568d3db5c127
SHA1 hash: 02d39c45d304208eb55d19e3efc1bf920324f2d9
MD5 hash: 3a0adc0009b659a108b8ddc3d7ea171c
humanhash: victor-fix-charlie-winner
File name:30072020.pdf.zip
Download: download sample
Signature AgentTesla
File size:480'686 bytes
First seen:2020-07-30 07:44:15 UTC
Last seen:2020-07-30 08:49:32 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:cNFPxDuR2v1rB4Kci9LBIdPyWQaA8t/Xk/LffP:cNC0jd6d65aJlXULfn
TLSH 4EA423C08E747BCD21B01D7EE09355EEA531F4150AA4FB7BF22804E97E9876D42D4A6C
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sellerbulknewscom.top
Sending IP: 106.75.74.104
From: International Purchase Manager <sales@sellerbulknewscom.top>
Subject: 30/07/2020 Remittance
Attachment: 30072020.pdf.zip (contains "30072020.pdf.exe")

AgentTesla SMTP exfil server:
mail.cjcurrent.com:26

Intelligence


File Origin
# of uploads :
2
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DataStealer
Status:
Malicious
First seen:
2020-07-30 07:46:06 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 960cb20824a37a302d5741fc9d62e89852a3b9fe33a70f08ef136cc60def4705

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments