MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9eea541ed0c69e64ac52d8ac29333c4878a91328179cf03c3979530009993dd2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 9eea541ed0c69e64ac52d8ac29333c4878a91328179cf03c3979530009993dd2
SHA3-384 hash: 8728ff9b749ba03733e8ebff86a9178ae3d70f45eff2b0bba22a08868d840574d87b13cc395fb20b877e86aa4ca54241
SHA1 hash: 5c1ef4a46fd965bd28992202c399a2a308b954d0
MD5 hash: 69e290e5cf370c22f5936253a8a5f0b6
humanhash: spring-two-pasta-juliet
File name:po.zip
Download: download sample
Signature AgentTesla
File size:389'263 bytes
First seen:2020-06-28 18:10:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:LssqaUafIlCHPI1BYoV8vm1Iz+oUwJLfy86fAyPl8WppUilEoyZ1Zn9N5CrSbCdx:RqajIlYI/Y+8vm14+oUlIyPGW4WmXxCN
TLSH 4D84236C6C583D63F81913B6A9EF11B67EAF05EF894460EA613B423E9960D41E3C2D24
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: firemaxcambodia.com
Sending IP: 103.99.1.174
From: Firemax Engineering<accounts@firemaxcambodia.com>
Subject: Project CPP FF
Attachment: po.zip (contains "po.exe")

AgentTesla SMTP exfil server:
mail.dianaglobalmandiri.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9eea541ed0c69e64ac52d8ac29333c4878a91328179cf03c3979530009993dd2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments