MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c9d8cd7558fffa58e1f1b9519b7443ab4c5b7a42152b209f74caf54c9b0c3d66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | c9d8cd7558fffa58e1f1b9519b7443ab4c5b7a42152b209f74caf54c9b0c3d66 |
|---|---|
| SHA3-384 hash: | 0b9589577cfe5694c6f91af559f1c46b0385b5814022cd823389aff406d1acf212547b1bb181b33eb6c98525b07e4292 |
| SHA1 hash: | 5dd050190b6f2558c1ce2e367a54a7ca07ad82a8 |
| MD5 hash: | 11871c67beef448a125fdffabdcab18b |
| humanhash: | paris-zulu-pennsylvania-snake |
| File name: | Company Brochure.arj |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 405'623 bytes |
| First seen: | 2020-08-08 08:14:27 UTC |
| Last seen: | Never |
| File type: | arj |
| MIME type: | application/x-rar |
| ssdeep | 12288:Ioswr7bkXyKkcJYFGgpKYkSSV5Q0B58sb:Kwr7grkc6P8YkvV5j |
| TLSH | E18423E01FD1AEC40647C5498EEBAB7F5C254B2BD4A2BED90090B11FCBE171427FA991 |
| Reporter | |
| Tags: | AgentTesla arj |
abuse_ch
Malspam distributing AgentTesla:HELO: serve0.hshgroups.co
Sending IP: 104.168.166.26
From: "Lili Wang" <info@hshgroups.co>
Reply-To: raymondjeffery316@gmail.com
Subject: Re: Order List
Attachment: Company Brochure.arj (contains "XxQQxiatVhWXKPN.exe")
AgentTesla SMTP exfil server:
mail.sardaplywood.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-08 08:16:08 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.