MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a81b6946f231ea574e2f32b85f29c7e3601f196c74f45b2bf2e565c0542b159b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a81b6946f231ea574e2f32b85f29c7e3601f196c74f45b2bf2e565c0542b159b
SHA3-384 hash: d09235104ff9dd712818ba27ad1cf3a8134533680efce2e043b24bafda53306b448741e93d1c4a2276df9b47ffe4fd3c
SHA1 hash: c323bd079762cdb1d039134ed2b1b47aa45d9d69
MD5 hash: 9df8b94c748dcef5f2a71039a4b05cef
humanhash: twelve-river-wyoming-fifteen
File name:PO 345678..rar
Download: download sample
Signature AgentTesla
File size:384'551 bytes
First seen:2020-07-24 07:55:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:8d2QuZdSctuIZ7ZYgNB914bRJ5TRe8OqK0v/A9krgkKp5ueQP6A8uLBi:Fbuc7ZYk4NTQtFkrgkk5jQP6AvA
TLSH 728423530A35A1BAFB61C6F1D2A226133DB5D9123F0BCA03948D9C1EB1E54C3CEBD246
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.confidencegroup.co
Sending IP: 162.144.54.78
From: Jose Luis Carbacho Tamayo <edi@zaccaria.com.br>
Subject: PO 345678.
Attachment: PO 345678..rar (contains "PO 345678..exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-24 07:57:05 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar a81b6946f231ea574e2f32b85f29c7e3601f196c74f45b2bf2e565c0542b159b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments