MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97cb0a43d746c1ae91abe3fc08e7b69cd5979f695dbcd42c0130afb1bfe61afe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 97cb0a43d746c1ae91abe3fc08e7b69cd5979f695dbcd42c0130afb1bfe61afe
SHA3-384 hash: eeee2fee88fab203f2981512bff36c521202315cac9ecae07cbf37fec121681570b5bf1b5a752f4c97463984692c4917
SHA1 hash: 56010c5853a6a225e2bf661e8e0001295e480de3
MD5 hash: b81306b7ff7101ad9381ff098576b2fe
humanhash: venus-timing-pasta-montana
File name:Proof Of Payment.rar
Download: download sample
Signature AgentTesla
File size:401'295 bytes
First seen:2020-05-06 10:46:35 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:hrBEgHlhS5prIzoNXxqckX4Ld0jPbsCrKO:hrBBTtz84b47qKO
TLSH DD8423760774F7ABB7F753629A0DA1848CAF3E1485392FFB2D00B6A429D35A1E078850
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: duba.com
Sending IP: 89.40.114.211
From: ngcume.siya<allan@melvin.gq>
Reply-To: <bonqanim@gmail.com>
Subject: Fwd: Payment Notification
Attachment: Proof Of Payment.rar (contains "Proof Of Payment.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Nanocore
Status:
Malicious
First seen:
2020-05-07 03:59:33 UTC
File Type:
Binary (Archive)
Extracted files:
41
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 97cb0a43d746c1ae91abe3fc08e7b69cd5979f695dbcd42c0130afb1bfe61afe

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments