MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a5e17ef8f03d056aa4506a008405c3bb7614810b2c3f10ca249b648cd8c089e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a5e17ef8f03d056aa4506a008405c3bb7614810b2c3f10ca249b648cd8c089e7
SHA3-384 hash: 15b81e13641a54cef9be799e627215c66afcd132e6f7282895e70b56077c26cda7b1fcb4d05ff22ff519536a230a6077
SHA1 hash: 7e2d86592049eba902c9188085e5427816864e8c
MD5 hash: a2ae4ec90ad259dae7906e530088f29b
humanhash: hydrogen-island-carolina-carolina
File name:MIDMAY TECHNOLOGY.zip
Download: download sample
Signature AgentTesla
File size:553'080 bytes
First seen:2020-08-31 08:29:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:/vdyr6ZiTl68Wz3j0x+oz/fXc9kKYahnzv9ev7P0Y:/Fw6ZZxa+oz3TKYahzAj
TLSH 93C42385058F30427DCEA9009548FBAF5F2FEA46C60A66C2343AC3661F4D69F98945FF
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gains.hificlouds.com
Sending IP: 131.153.48.114
From: lynn <sales@med-may.com>
Subject: RE: Inquiry Urgent Quote
Attachment: MIDMAY TECHNOLOGY.zip (contains "MIDMAY TECHNOLOGY.exe")

AgentTesla SMTP exfil server:
smtp.polocraft.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a5e17ef8f03d056aa4506a008405c3bb7614810b2c3f10ca249b648cd8c089e7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments