MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b669786c9c8f92ee1477100545f5307b60ac85d2be0ecb4ecb9ea087c3530f80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b669786c9c8f92ee1477100545f5307b60ac85d2be0ecb4ecb9ea087c3530f80
SHA3-384 hash: cd552db526fd4246d885f1748fa9157091e08c17472cd1c0df0fd3b63d8dd3633ef63dd6c849032b1b33b44a9d38c5df
SHA1 hash: 8a2dfbc8dc77393cd63211c73c9025e1fc6a5e2c
MD5 hash: 3e634ffe3fcf8566fdf59ec746f396f0
humanhash: one-mississippi-pennsylvania-july
File name:PO_28710.zip
Download: download sample
Signature AgentTesla
File size:326'108 bytes
First seen:2020-07-13 06:20:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:IhlwnXhrMObY2YUxhDiu+VjUFet0EOoRC/Nw7tSzf7DuSdiDhXCmNdbPADk:COXm0YXK+VoFewo4/Nf7KSoFSmNd8g
TLSH C66423D6B143EACB3FD27DBA4496F731B1750DB03125DBB1C922CA48DC0C4AA8986763
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: srv.newton.co.id
Sending IP: 103.253.115.37
From: Banpuindo <medrizon_maswar@banpuindo.co.id>
Subject: PO_28710
Attachment: PO_28710.zip (contains "PO_28710.exe")

AgentTesla SMTP exfil server:
smtp.altrii.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-13 06:22:06 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b669786c9c8f92ee1477100545f5307b60ac85d2be0ecb4ecb9ea087c3530f80

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments