MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c4932083c19f48f0d2b504417c521f89adaf673ac793742e29f2017c46b0f6ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | c4932083c19f48f0d2b504417c521f89adaf673ac793742e29f2017c46b0f6ee |
|---|---|
| SHA3-384 hash: | bf133032d76dbeace1e447d029046be7592bb5876ee225362fda70cfa88f64e730b0d16f39edf63d5e472b36d6819601 |
| SHA1 hash: | 600b7ea1a1e24193fb370ad76a1f8240f80235ea |
| MD5 hash: | bb7e146bf66e5e48c1e9ca92d5b4482d |
| humanhash: | batman-nevada-fruit-fix |
| File name: | PO_20202602.ace.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 837'511 bytes |
| First seen: | 2020-08-17 13:54:40 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:RgWSekLsHmx7gZZrLnY5zmuhkgD/ffqrtuD2rVGZsCqfx3RdyAg5/lUYf07usArG:iWmPxIXYJmIb74tkkVtHdqxs7t |
| TLSH | 9105335878022C6DA238C590FF4991D3E23E76D1646A7C6E08249B833DCDC69976DCEF |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: pluscargoecuador.com
Sending IP: 103.99.1.149
From: karen.curtidor<karen.curtidor@pluscargoecuador.com>
Subject: RE: Urgent Request For Qoutation(RFQ_#20200219)
Attachment: PO_20202602.ace.zip (contains "PO_#20202602.ace.exe")
AgentTesla SMTP exfil server:
mail.framafilms.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-17 06:40:02 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.