MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c861ad66df4fede69454ecef38faefa522389002af267ebe034d1c8f9f8f87d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c861ad66df4fede69454ecef38faefa522389002af267ebe034d1c8f9f8f87d0
SHA3-384 hash: 68a2b92c2a5aca09ec9c5162eb6e6dc2e07efd87ae2647ba6a525ab1242627b0f087e81f88bc08285aa2162038c28cbb
SHA1 hash: 6b584113e957d95ccd118aea2dea70d0480f41e5
MD5 hash: f573ef59cf5b1d72e96c16d7b92d18db
humanhash: wolfram-football-september-nevada
File name:090000000090000000.xz
Download: download sample
Signature AgentTesla
File size:418'531 bytes
First seen:2020-06-25 07:54:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:0caNX/JDqaOivnud6wc3mQF4EWbuhsPFXV8vecsEmBoi++piOLxjPvn/HDWWnD:0VNvlq0nud673msWbNPzB9Boi+4BXyWD
TLSH 599423EDB483725888C0693BD30E6869D6DF5CE57A693459237486F4874ACEE024C3FE
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: [185.234.219.109]
Sending IP: 185.234.219.109
From: Francisca<vendas@anhembi.com.br>
Subject: SOLICITUD DE COTIZACIÓN
Attachment: 090000000090000000.xz (contains "090000000090000000.exe")

AgentTesla C2:
http://demirdogen.com/origin/inc/c463f64bb0e1a3.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c861ad66df4fede69454ecef38faefa522389002af267ebe034d1c8f9f8f87d0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments