MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a778a7cb1f8e0433d2fffffdde8826c4af9924a6f5e81153cb4d09a8f08f6654. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a778a7cb1f8e0433d2fffffdde8826c4af9924a6f5e81153cb4d09a8f08f6654
SHA3-384 hash: 4f7d32ca120c724a498b4bb766ce0fa3f811c00d45a0bea27843b95ffd6d56a7b9de1015e66a6eecf435aade1a25c670
SHA1 hash: 438052b3f237bbbefdef11205fac39ec438223b2
MD5 hash: c748f904cc1e348fb63b7ba8750aec1f
humanhash: beryllium-nine-venus-jig
File name:SOA.gz
Download: download sample
Signature AgentTesla
File size:374'156 bytes
First seen:2020-07-12 16:28:54 UTC
Last seen:2020-07-12 17:04:16 UTC
File type: gz
MIME type:application/x-rar
ssdeep 6144:78vij+nyxM336Kia/2OlZ9hR1WNHQHSwpDmyNmwyd5goCkD8sfg4IFPvUmRFJYlh:mij+yxm31r/2OZh3+HQHSEDNNPyd+oCu
TLSH 0A842340DDB83F4D008F464663F28102DBE5EF9CAE49E23836878B51D9A5A37A811EDD
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mediaminds.biz
Sending IP: 95.211.211.232
From: Ahmed Akram <ahmed.akram@mediaminds.biz>
Subject: Re: Updated SOA
Attachment: SOA.gz (contains "SOA.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-12 16:30:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz a778a7cb1f8e0433d2fffffdde8826c4af9924a6f5e81153cb4d09a8f08f6654

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments