MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9ffef2dd525e6a84a57ec4806b5c3c93716f766f913de6ad5096eee89ef74c61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9ffef2dd525e6a84a57ec4806b5c3c93716f766f913de6ad5096eee89ef74c61
SHA3-384 hash: 3bceb4c070566fe4a270d87e9403d5c96b1ff15d00a6017c095233293d8c5d78337e9dfed305f6c33a4899f5d37bfe53
SHA1 hash: 896d62bf3114b38dac91cd4c74656a1c78377e24
MD5 hash: 14891ae90271d0c40a4ab7404b74b699
humanhash: paris-april-timing-mars
File name:Our Ref MIDLGB31..rar
Download: download sample
Signature AgentTesla
File size:336'032 bytes
First seen:2020-07-02 07:54:58 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:zJ1E1wehlaTpNw9MHpVcPsvYbjdg+ufN/+JptS0OFqLJ8jJ+qIbey24fy9rLiRwO:zJhTpNw+HpyPswHdgHV/+JpA0OFFGfAQ
TLSH 126423D01DDBEF81B286A51839BFE4949221BE197DD189A449DE4FE42C4935B0BFF0B0
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hsbc.com.vn
Sending IP: 103.99.1.149
From: Hieu T M NGUYEN<hieunguyen@hsbc.com.vn>
Subject: Ref: Confirm Remittance
Attachment: Our Ref MIDLGB31..rar (contains "Our Ref MIDLGB31..exe")

AgentTesla SMTP exfil server:
mail.mystboutiquehotel.com:587

AgentTesla SMTP exfil email address:
fom@mystboutiquehotel.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-02 07:56:07 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 9ffef2dd525e6a84a57ec4806b5c3c93716f766f913de6ad5096eee89ef74c61

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments