MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9cfa2b536a53d145f975cf578cf787ceee577d19c377d18eb428865116e3adcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9cfa2b536a53d145f975cf578cf787ceee577d19c377d18eb428865116e3adcf
SHA3-384 hash: 82d2d8382566f2bf97a64d325897ab53499b763ada35ee0f5928e330fc048b77c29137728e3dd50f2b33fec316776b78
SHA1 hash: a9109a885b83f26caa6937ef0efa0055e0f6fd92
MD5 hash: c2b3cc8a876aaad5b24fc3b020fede94
humanhash: princess-chicken-early-tennis
File name:Payment Follow - up Monthly SOA.r00
Download: download sample
Signature AgentTesla
File size:1'180'901 bytes
First seen:2020-05-04 18:33:38 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:+jkqn7TWT6vyuzPJDb+BBaVjT0oMSzxjFcEt8uT7H4dloSb7dthU:MnfWDyFVT0mjuo8M7uloS/DC
TLSH 514533F380E6FD77C3947BB0C2B5999B918B60B7280F7DA8D641870D65C02E919A83F5
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 163-172-76-20.rev.poneytelecom.eu
Sending IP: 163.172.76.20
From: Muhammad Saleem <finance@ibrahimigroup.com>
Subject: Fwd: Payment Follow - up & Monthly SOA
Attachment: Payment Follow - up Monthly SOA.r00 (contains "Payment Follow - up & Monthly SOA.exe")

AgentTesla SMTP exfil server:
mail.pruthiexports.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-04 18:36:07 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 9cfa2b536a53d145f975cf578cf787ceee577d19c377d18eb428865116e3adcf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments