MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4f10c95f52347a4c696d10c15a3097a35e1c8fd5deeb4c13d7b8557d4cf0479. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b4f10c95f52347a4c696d10c15a3097a35e1c8fd5deeb4c13d7b8557d4cf0479
SHA3-384 hash: 7d5d9fd66ee4ef85eb4ea54980daa42e0aa117d01627c27afbfbe784dfcb2d1aa12ac13c0eb3ed856331c177eea1aed8
SHA1 hash: 5a60d2d5a0d673e472667a667a2b12208b1d3f9c
MD5 hash: 4b3bafdc8fc5d6758f6b4c87c1e465c2
humanhash: utah-fix-coffee-west
File name:proforma Invoice_pdf.gz
Download: download sample
Signature AgentTesla
File size:427'223 bytes
First seen:2020-05-13 10:57:56 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:wg+nwnjxRzjOiSedM4VzRPZhQ1EK+hIUjBtYq/6mSN2GRccov+wDOC:OnwnLCV4VZTQ1EwU1mqCZN2qRovBOC
TLSH C5942347DF5AE2B3B903CCA2F903BD01E7D5458EDB9888F449A71F1CAE8794361096C5
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: staging.maykenbel.com
Sending IP: 195.12.49.182
From: Mr. Samean Sok meth <mdc05@dynamic.com.kh>
Subject: Urgent Notice...Invoice does not bear bank details!!!
Attachment: proforma Invoice_pdf.gz (contains "proforma Invoice_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 11:37:13 UTC
File Type:
Binary (Archive)
Extracted files:
266
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz b4f10c95f52347a4c696d10c15a3097a35e1c8fd5deeb4c13d7b8557d4cf0479

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments