MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4054e767cc9c235ab4434687a7bb9937845f435c88089eabf3d516b07055221. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c4054e767cc9c235ab4434687a7bb9937845f435c88089eabf3d516b07055221
SHA3-384 hash: 1e81bdcaa1f20b648ab6228e2e01307df85033ee29d465bef4cc484abc5f831d47ed267ce0ca0d6b09aeab340d02fb52
SHA1 hash: af54ac37ac38ed1440f295a3bffcde782f13c193
MD5 hash: 42d6e28bf71e9034427875d1d757eada
humanhash: robin-neptune-sweet-sixteen
File name:1.65MB.zip
Download: download sample
Signature AgentTesla
File size:413'784 bytes
First seen:2020-06-29 06:09:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Uk51eOlArqAMPgmGCSQCxO6jhSl1KBpWH1uAa:UHOerAGDhPFTN
TLSH EA9423F5656FE252375E33A0D4B39462B3E2454DF59E25990A08385BBFDF2E00D98087
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: s111-ir-cpanel-trade.maindns.net
Sending IP: 185.165.116.18
From: Martina Esposito <pt.silbers@yahoo.com>
Reply-To: sales.silbers@gmail.com
Subject: Copy Of Payment
Attachment: 1.65MB.zip (contains "1.65MB.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Bluteal
Status:
Malicious
First seen:
2020-06-28 22:37:05 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c4054e767cc9c235ab4434687a7bb9937845f435c88089eabf3d516b07055221

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments