MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a76f407893d7d8961ec227ce4bdf382a4c90bee0a18245ba14f7171ffa800cfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a76f407893d7d8961ec227ce4bdf382a4c90bee0a18245ba14f7171ffa800cfb
SHA3-384 hash: b7ecc9ab76f1d469b6ec6a6b1091b7b5d1db8686c6444a366e3496218fce743ccde9f1e8e38cad8380e01381b4780de4
SHA1 hash: 9e406049aeb2e13f4d60f890612d848dfa93e5e0
MD5 hash: 87c412498ba67ac65c2aa7e348d26d44
humanhash: wyoming-princess-hot-iowa
File name:attachments.zip
Download: download sample
Signature AgentTesla
File size:453'505 bytes
First seen:2020-07-07 05:44:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:JgVcKo3WDVhtfNA4SqCM7X8TgmS4hbAzwV:JBKvhtVQqCM7MTG4hbAzq
TLSH B8A423099B82EC02F7FF36FA57851D0CFDAEDA066607B7CBB84310164C991182D67DA6
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: afnet.net
Sending IP: 45.138.172.20
From: Lai Yun Loong<rkz@afnet.net>
Subject: purchase order.(PO-O3465-0001)
Attachment: attachments.zip (contains "PO-O3465-0001.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-07 05:46:05 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a76f407893d7d8961ec227ce4bdf382a4c90bee0a18245ba14f7171ffa800cfb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments