MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c85be2db542439c866095092c035fb14b949a228e6349c72df98b123514e66be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c85be2db542439c866095092c035fb14b949a228e6349c72df98b123514e66be
SHA3-384 hash: e803d84f2c3a907399e80f2cac70940132ab1641fdaef4647d0a1d1f368c35594adfba1a86e923173fd256cbc98bce0a
SHA1 hash: a25905d353e54caa6f15b2bd3421fc96b67b6a78
MD5 hash: 6d27f79641eb70b9ef641af185190701
humanhash: comet-quiet-fish-batman
File name:invoice.pdf.z
Download: download sample
Signature AgentTesla
File size:280'462 bytes
First seen:2020-07-13 11:31:05 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:0o1Be37o7Vb6Pl7pLA00qdxPtfnbUGDweUcAj9LD6SbHcoqbgBEM:d1i7o7Ve97apqDJbFDatj98oqal
TLSH 6554234F91CAC90497A1FA5C4B30CB36921721A46046EF7E46C67ECCED8CE8936DD96C
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: alkuhaimi.com
Sending IP: 37.48.83.10
From: Accounts Department <rud-division@alkuhaimi.com>
Subject: wire transfer.
Attachment: invoice.pdf.z (contains "invoice.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-13 11:33:04 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z c85be2db542439c866095092c035fb14b949a228e6349c72df98b123514e66be

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments