MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c22f6b2a9feb3f0c6c13c6dc93aa694972f00dfb8a18bed6ace8ffd7370d1ed9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c22f6b2a9feb3f0c6c13c6dc93aa694972f00dfb8a18bed6ace8ffd7370d1ed9
SHA3-384 hash: 1f51fcfb1add5b523377072cdd9d8f274bf19d90e75643136e35cfb9d94a61c5552a9c157b05ff1ff39876fb69a30b12
SHA1 hash: ed2416b4eb7b96b0c66fa567d0911f12cb38f2bd
MD5 hash: fac0b7143d1afe97e945cd9c214349a9
humanhash: venus-london-missouri-monkey
File name:MEDIFORM SA COMPANY PROFILE.zip
Download: download sample
Signature AgentTesla
File size:497'200 bytes
First seen:2020-08-19 12:49:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:VkXd4Mw8XQMUQERsoKZcsXPZFVgxw/1Z1wF6wto:u5QLs7FVwceq
TLSH 03B423784AD632480CC240D6BDD39A4E10C3A713AD09BF6FE1715FAC4DA66C6F68665C
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: serve0.tacadenaplc.pw
Sending IP: 104.168.253.8
From: Mediform S.A<mediform.s.a@hotmail.com>
Subject: Re:Fw: Request For New Inquiry RFQ
Attachment: MEDIFORM SA COMPANY PROFILE.zip (contains "MEDIFORM SA COMPANY PROFILE.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-19 12:51:07 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c22f6b2a9feb3f0c6c13c6dc93aa694972f00dfb8a18bed6ace8ffd7370d1ed9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments