MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b50778ed0b7e052c9f210ccab085653e4a8fba360aaf653821c9efb48d4b2ef6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b50778ed0b7e052c9f210ccab085653e4a8fba360aaf653821c9efb48d4b2ef6
SHA3-384 hash: d7c8f63fb4a62c23c5aaf0b21d0a1b229f659fb7ff83b0054629b05345586a3aee4392584c7eba778aaa63e074ab7ebf
SHA1 hash: ddf5cf755ad453dbd736e61675591b0c2cfb2da5
MD5 hash: 0e3cc0df34b0e9a9a913fd7985d31842
humanhash: lithium-black-pluto-pasta
File name:MVHEILAN_INV.pdf.arj
Download: download sample
Signature AgentTesla
File size:447'724 bytes
First seen:2020-07-24 07:58:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:zWaCGRPkjN//84ZWEL8GW5GoGfxnmHRymrGTD7Ii92k:zj5mjvoGfVmiTYi0k
TLSH 7C9423816B93BF68C1B05666908AFAFA6C8FDC08DBD3C1687364DB52171049561F7FE0
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: glinksoft.com
Sending IP: 64.46.34.61
From: ZHOU XIN TONG(Mr.) <operation1@yndmarine.com>
Subject: MV HEILAN SONG V2004 - Bunkering INV.
Attachment: MVHEILAN_INV.pdf.arj (contains "MVHEILAN_INVpdf.exe")

AgentTesla SMTP exfil server:
secure231.servconfig.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-24 08:00:09 UTC
AV detection:
33 of 46 (71.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b50778ed0b7e052c9f210ccab085653e4a8fba360aaf653821c9efb48d4b2ef6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments