MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cda88f49ebd6c0cdb044a093fcac6d9b055bff0433655d74954552e7271c0958. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cda88f49ebd6c0cdb044a093fcac6d9b055bff0433655d74954552e7271c0958
SHA3-384 hash: 4be4439e3afdaa57c1b60bfdfa7ba6d961c4db9cb6899643acae296bf483b1a70c5d0b51fb95a12259f13e44074630a2
SHA1 hash: ad131b1190853014fd836a7c032503ad71b87146
MD5 hash: 1a2e788879093c99c26c70af3ee19a96
humanhash: moon-idaho-ten-avocado
File name:29 _April_Delayed_Shipments_23_04_2020_Pl_HongKong.7z
Download: download sample
Signature AgentTesla
File size:1'290'179 bytes
First seen:2020-04-29 19:30:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:Zn89qeDo2dM+15tM7L82uwnt8BQJABnTlhJCeKFFPNYuDcdmefTgmuQ:Zna/o2r1TMjuwoQJaBhJC9JN+gc
TLSH E255338BE4EE2D9A1CDD64B716265D80A80EFAC8933EB1E311F623C171DAE3D144E185
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp.zsuite.io
Sending IP: 69.16.192.208
From: Sarah Mei <smtpf0x@instantofflinepresence.com>
Subject: Pandemic Delayed Shipment
Attachment: 29 _April_Delayed_Shipments_23_04_2020_Pl_HongKong.7z (contains "29 _April_Delayed_Shipments_23_04_2020_Pl_HongKong.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 19:36:07 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip cda88f49ebd6c0cdb044a093fcac6d9b055bff0433655d74954552e7271c0958

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments