MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c5a0aef681ae2a0b3cb7f755fafdd52fd523914716588f971c17566d78806025. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c5a0aef681ae2a0b3cb7f755fafdd52fd523914716588f971c17566d78806025
SHA3-384 hash: f5addb35dac5ad4f33180881597761b828d013bce7418c9808280c3663bc83c07b0a2d18f308ace7be4c1668ae48a6ed
SHA1 hash: a871ac223971df08c31a7223a0a67a90f5867b86
MD5 hash: 7efd3655a5ecf3400c730e47999ec159
humanhash: diet-steak-lamp-mississippi
File name:Statement of Account for Payment.r11
Download: download sample
Signature AgentTesla
File size:435'062 bytes
First seen:2020-05-18 08:01:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:mcLq/RJD6y9PNyCEf4yyDbDPGqrgixVMNvF6:mcLqZV19PwoLtrgfNvF6
TLSH 9B9423218E6132998071153BBF199D6C242FE74964EAB27D0ABDDAFF1350BC94940F74
Reporter abuse_ch
Tags:AgentTesla r11


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Account Lun <lun.winglandshipping@bk.ru>
Reply-To: Account Lun <lun.winglandshipping@bk.ru>
Subject: RE: Request for Statement of Account as of 31-May-2020/// Payment
Attachment: Statement of Account for Payment.r11 (contains "Statement of Account for Payment.exe")

AgentTesla SMTP exfil server:
smtp.desmaindian.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 08:36:07 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c5a0aef681ae2a0b3cb7f755fafdd52fd523914716588f971c17566d78806025

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments