MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9d4efd52e0e8e9093e6475378e4d7d8ee676c92dbc98f783f761bf5c429ca75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b9d4efd52e0e8e9093e6475378e4d7d8ee676c92dbc98f783f761bf5c429ca75
SHA3-384 hash: aa24813e8ec813591f3cb4064b4c77eb19ca9b423ba209cf2a7b3b4c1017922dad2d9c243744357a811424a424d575e9
SHA1 hash: 82b2a1abe75bf8b5d3907e56a560bcbe0c26231b
MD5 hash: 4d55b34c1aa44d2ae5dfee21a52ed6ba
humanhash: jersey-west-montana-william
File name:CONTRACTS003020,pdf.rar
Download: download sample
Signature AgentTesla
File size:429'280 bytes
First seen:2020-05-05 07:48:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:+wFp2Bqw9IB7CRSnfyh+XdrpEg4JMTJn45:+wFgFI1yh+XTEgEMFn45
TLSH 9E9423643E76101B59C68293A21143D8D153304CECA9A7DFA727D3B92F17E3ACB1B897
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server112.spotservhost.com
Sending IP: 144.217.69.193
From: Mohamed <gold_admin@alosra.com.bh>
Reply-To: Mohamed <gold.admin@alosra.com.bh>, Mohamed <gold.admin@alosra.com.bh>
Subject: Contracts Copy
Attachment: CONTRACTS003020,pdf.rar (contains "CONTRACTS003020,pdf.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-05 08:36:25 UTC
File Type:
Binary (Archive)
Extracted files:
16
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b9d4efd52e0e8e9093e6475378e4d7d8ee676c92dbc98f783f761bf5c429ca75

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments