MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abc97334a23f1e67e220edba03108ad6a5e5784578a2c97f0318862051218cc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: abc97334a23f1e67e220edba03108ad6a5e5784578a2c97f0318862051218cc4
SHA3-384 hash: 167b4322652abb501780856ec4b5b0ed49e01900462416d6e0abc9e9186529bde820424d08dc7aa5b1f0073e7a21ff3c
SHA1 hash: 835de51d326b8f595d760e2ddcafedaeb03bdad4
MD5 hash: 8b74ffa00e6bd3bdb2953e7381437713
humanhash: september-ten-bakerloo-maryland
File name:MTS-P-026 REV.02 CIRCULATION PUMPS HOT WATER SYSTEM.zip
Download: download sample
Signature AgentTesla
File size:392'935 bytes
First seen:2020-06-08 05:10:22 UTC
Last seen:2020-06-08 09:42:33 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:As9xHI1L+4vs0Vf0Sa6zdz0NYp2k6FTaY5IsOdc0fweWzQ9bak3i23bh1VCl+R:RXo1Nvzba6z90E2kkBiWz8aq3bdP
TLSH DB8423CF8C5CA1618BCE204489322C95945B7FB5762D6A9CCACD1C7DEA99D4C8AC0ED3
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: intermass.net
Sending IP: 209.58.149.66
From: Rajath Ramachandran <rajath.r@intermass.net>
Subject: REQUESTING QUOTATION FOR SEWAGE LIFTING STATION PUMP-PGC 380@RAS AL KHAIMAH
Attachment: MTS-P-026 REV.02 CIRCULATION PUMPS HOT WATER SYSTEM.zip (contains "MTS-P-026 REV.02 CIRCULATION PUMPS (HOT WATER SYSTEM).exe")

AgentTesla SMTP exfil server:
mail.mytravelexplorer.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-08 02:41:35 UTC
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip abc97334a23f1e67e220edba03108ad6a5e5784578a2c97f0318862051218cc4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments