MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 caf65e84911a0a9c41c63bde364f52cfe70b7f768d0c5daac67501c5f3fbf0fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: caf65e84911a0a9c41c63bde364f52cfe70b7f768d0c5daac67501c5f3fbf0fe
SHA3-384 hash: 811557d028c219bce87e5cfcb1890d1cebfb483f5cf2e90a541b6f15221590d11bed8fed6485fedf384a8541cf4cadff
SHA1 hash: 044f295e9efee1ae76489d1c0067c0dad9efde3e
MD5 hash: 5edd90109dbf16af3b8bc2d479c30b9c
humanhash: xray-massachusetts-moon-kilo
File name:soaMay2020.pdf.arj
Download: download sample
Signature AgentTesla
File size:521'569 bytes
First seen:2020-06-10 18:12:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:o+xyutcVT5LcoTgaB062fSpRpyTWECXNkkMmVrck2:oBum5vTgaefSpRcTW9qkMm0
TLSH 82B4231012BBAC7D451F0E1F24C2DD581BBA84E0A8D62945F35093E991B7A07ECADFED
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: host.iteamweb.com
Sending IP: 209.59.138.164
From: Sara Zheng <sungmin@sungmin.cc>
Subject: RE:MAY 2020 SOA rev.
Attachment: soaMay2020.pdf.arj (contains "soaMay2020pdf.exe")

AgentTesla SMTP exfil server:
secure231.servconfig.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip caf65e84911a0a9c41c63bde364f52cfe70b7f768d0c5daac67501c5f3fbf0fe

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments