MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f2a5e193af5c82863ba47494c742585247a3acd6f0c160cc9576a90694a0509. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9f2a5e193af5c82863ba47494c742585247a3acd6f0c160cc9576a90694a0509
SHA3-384 hash: 0eaa7c04712291443c6180fdaa10151c07e1479adbe953ae87acccad0f799e953d1335eea6b5e23ce6351d7a102b4312
SHA1 hash: ab0fd4549419c0044fd6bf481617a3143207b6cf
MD5 hash: 58b7cdb925f7afc7ae4dfa232fd674ac
humanhash: texas-freddie-spaghetti-football
File name:june invoice 06072020.zip
Download: download sample
Signature AgentTesla
File size:436'801 bytes
First seen:2020-07-07 09:00:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:SWXSRnCpDeCcXOdPSgJSpCUWPTHKlHlGCHb:mVtCcXOdPSgACUJkeb
TLSH F294239890235EC9FCB20A34F7AB7413A46EB7819E98F719DDF55348A048753847ACE3
Reporter abuse_ch
Tags:AgentTesla CHN geo zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.cinderllafashion.com
Sending IP: 45.95.169.119
From: 銅鑼生產計畫課-吳彥瑤 Nina <nina@pahsco.com.tw>
Subject: June Invoice.
Attachment: june invoice 06072020.zip (contains "Z2ktx9IeQBnKGIm.exe")

AgentTesla SMTP exfil server:
smtp.mail.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-07 09:02:07 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9f2a5e193af5c82863ba47494c742585247a3acd6f0c160cc9576a90694a0509

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments