MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b37950e9376965942f8dddc16f447d9b93c7c286917c9371b0e83d06f7700bbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: b37950e9376965942f8dddc16f447d9b93c7c286917c9371b0e83d06f7700bbc
SHA3-384 hash: 71a8edf7f9cddc4b03bc1a9c028c0d1ce46bc5441b06750f6d567f46e1d44abc38da7a69b05fc12576eb0489dff599ce
SHA1 hash: c104ea294467fc2f06f25831add612ec331d1b74
MD5 hash: 93121dc283326135820472935dfbef7c
humanhash: tennis-kitten-carbon-georgia
File name:Documents.zip
Download: download sample
Signature AgentTesla
File size:492'253 bytes
First seen:2020-06-10 17:55:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:lc5MXUEK0cA/uJtURERdnTbaW7gEYwB7hnbBkX3:lc5MkXJtbdnnHB7V+n
TLSH DBA423E5B8162AB6484DC2EE180ADA659759338205E4E7863F1F2D07EFE195346C2F33
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: magna-systems.com
Sending IP: 45.90.222.93
From: Silva David <harin@magna-systems.com>
Subject: Corrected documents for your approval
Attachment: Documents.zip (contains "Documents.exe")

AgentTesla SMTP exfil server:
smtp.1and1.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b37950e9376965942f8dddc16f447d9b93c7c286917c9371b0e83d06f7700bbc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments