MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b93d0b9aba7f210a8f68c64ef464fb2168f2d578bb3508ca4620422f0c5695bb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b93d0b9aba7f210a8f68c64ef464fb2168f2d578bb3508ca4620422f0c5695bb
SHA3-384 hash: eb2642c339183d14107f287335c55b703d4bef5aa17a72204824914f4ed8be6794a5e8954387f01d447533ebb0f04440
SHA1 hash: c2ab59828e09c11e414e97a772a18e7361c9b184
MD5 hash: cc790a92dfe986fe7b92219c96ff62a7
humanhash: xray-charlie-lithium-magazine
File name:SU6257848530.gz
Download: download sample
Signature AgentTesla
File size:412'304 bytes
First seen:2020-08-17 18:53:19 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:1SSpoQTBAjErKS2dnHAevO2pxGc5S6JX9ynJi6Y:1SmpO/S29ZO2HGc5SI9yJi6Y
TLSH 289423D1FCDEA3BA538348C5136ED8903DAD6E04DBADE8A0C1633F1576946941B1438B
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.cantalupilighting.it
Sending IP: 31.27.11.130
From: Scott Woodman <info@ecodelnord.com>
Subject: Purchase Order
Attachment: SU6257848530.gz (contains "SU6257848530.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-17 18:55:05 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz b93d0b9aba7f210a8f68c64ef464fb2168f2d578bb3508ca4620422f0c5695bb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments