MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d9a4669009e3aa6359066267db7cf43be108781f6048a9ea8a77acb87cd6b36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9d9a4669009e3aa6359066267db7cf43be108781f6048a9ea8a77acb87cd6b36
SHA3-384 hash: 36a7097ca5ff71ad6c377e0ceda90013b8312e645a1718987559330c51224e9e6cd0d57a5263181f64fb815994421329
SHA1 hash: 663906fdebbb13e85f66765c6cad179533bbe9fd
MD5 hash: c3f0f5b45cb1b4ecb62ae4c6c2d55a7d
humanhash: colorado-oklahoma-foxtrot-oven
File name:invoice.zip
Download: download sample
Signature AgentTesla
File size:354'226 bytes
First seen:2020-06-23 05:34:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:5wL+fm/KA7cpceEZ/PJo2+D6vqht++XbmLQV0jH1YoJUu6+sDiVKscmubFz:5wL+fmrnDn+2/Q++XF0jH+hutYi3c3J
TLSH 657423F450A0832BE22F9F70367CF4307359AE3DA68E0759E6DEC054851C94D6E2D3A6
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: brivercapital.com
Sending IP: 103.99.1.159
From: brian<brian@brivercapital.com>
Subject: Payment For Outstanding Invoices
Attachment: invoice.zip (contains "OPO.exe")

AgentTesla SMTP exfil server:
mail.aneeqllc.com:587

AgentTesla SMTP exfil email address:
marketing@aneeqllc.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-23 05:36:04 UTC
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9d9a4669009e3aa6359066267db7cf43be108781f6048a9ea8a77acb87cd6b36

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments