MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c738d3c04b09babb42a0d43eba56aa52dd4931febcb0614593cde68266b2907f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c738d3c04b09babb42a0d43eba56aa52dd4931febcb0614593cde68266b2907f
SHA3-384 hash: cef07e949bd00e1677895a3f33021934612b56bc58d47cc5eb45bdee6fdbbd4b7fb9d599ca3c17c2bce1e2b97cf454c6
SHA1 hash: 292174c1a5cd0a8242891ad081b8e5f59637e4a4
MD5 hash: 5022f923c72e99458b0589901c794677
humanhash: pip-burger-kitten-alabama
File name:0000001809.rar
Download: download sample
Signature AgentTesla
File size:438'981 bytes
First seen:2020-08-18 06:28:30 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:LwgzjrdAQ/tyA1HTnOYPvn8ZZK/1dH5trNf/:Lwa37hOcn8ZZK/1dZRJ
TLSH 4D9423BFA6C0E3FF272894F04F45D6894AB370BF5E152AE0D181596A2EED055C74B82C
Reporter abuse_ch
Tags:AgentTesla BBVA ESP geo rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.ketkata.hu
Sending IP: 194.149.40.70
From: Confirming.bbva@bbva.com
Subject: BBVA-Confirming Factura
Attachment: 0000001809.rar (contains "mmm.exe")

AgentTesla SMTP exfil server:
mail.materialsmiquel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Hacktool.CeeInject
Status:
Malicious
First seen:
2020-08-17 22:53:18 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c738d3c04b09babb42a0d43eba56aa52dd4931febcb0614593cde68266b2907f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments