MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca8ed7ceb64c0344aa8d92e53f0a93c4d66150fda5eeedcb96a0ed1f2488591c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ca8ed7ceb64c0344aa8d92e53f0a93c4d66150fda5eeedcb96a0ed1f2488591c
SHA3-384 hash: 029060019bc285858f34628916d0a5fb06f7fe8cecda3b04ef5ecd6ed965dedca4dc6584613739f72f181208fdd3bfba
SHA1 hash: 8e942840513070285eb123d0e00e5afeaddfe46c
MD5 hash: b6cab8d634b6647b4bab8f19f46e5fc9
humanhash: timing-delta-lemon-crazy
File name:QT200508092-01.z
Download: download sample
Signature AgentTesla
File size:389'038 bytes
First seen:2020-06-16 05:33:44 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:vhrNWNKNK73UMHn40xj4MHlD41Es8P5R2tGsjB2MyP6mQEloeWi:BNWNKM73Uo4K2SVPWl2MyP6hCoeWi
TLSH 558423DDA01A348E551A01DF040730F8CF366C75CEE8A2FBD36136E4EE9A66846FB585
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server0.jashlx.com
Sending IP: 23.254.226.60
From: Linda Lin <contact@jashlx.com>
Subject: INQUIRY QT200508092
Attachment: QT200508092-01.z (contains "QT200508092-01.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-16 05:35:09 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z ca8ed7ceb64c0344aa8d92e53f0a93c4d66150fda5eeedcb96a0ed1f2488591c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments