MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9d8cd7558fffa58e1f1b9519b7443ab4c5b7a42152b209f74caf54c9b0c3d66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c9d8cd7558fffa58e1f1b9519b7443ab4c5b7a42152b209f74caf54c9b0c3d66
SHA3-384 hash: 0b9589577cfe5694c6f91af559f1c46b0385b5814022cd823389aff406d1acf212547b1bb181b33eb6c98525b07e4292
SHA1 hash: 5dd050190b6f2558c1ce2e367a54a7ca07ad82a8
MD5 hash: 11871c67beef448a125fdffabdcab18b
humanhash: paris-zulu-pennsylvania-snake
File name:Company Brochure.arj
Download: download sample
Signature AgentTesla
File size:405'623 bytes
First seen:2020-08-08 08:14:27 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:Ioswr7bkXyKkcJYFGgpKYkSSV5Q0B58sb:Kwr7grkc6P8YkvV5j
TLSH E18423E01FD1AEC40647C5498EEBAB7F5C254B2BD4A2BED90090B11FCBE171427FA991
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: serve0.hshgroups.co
Sending IP: 104.168.166.26
From: "Lili Wang" <info@hshgroups.co>
Reply-To: raymondjeffery316@gmail.com
Subject: Re: Order List
Attachment: Company Brochure.arj (contains "XxQQxiatVhWXKPN.exe")

AgentTesla SMTP exfil server:
mail.sardaplywood.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-08 08:16:08 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj c9d8cd7558fffa58e1f1b9519b7443ab4c5b7a42152b209f74caf54c9b0c3d66

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments