MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ceff414fdb663579196bea272215d1a62f84ea60ebe5da6d6b140b3de0dd9f39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ceff414fdb663579196bea272215d1a62f84ea60ebe5da6d6b140b3de0dd9f39
SHA3-384 hash: 82e2b9f48788a0a1b809354e4568629344193e6b90c9a1b8ef92caa09a9ee1349c74df45b5957e62ca1b3ed1482d618f
SHA1 hash: 59ae5958f6220d6cc89c1349362302e6f4256bea
MD5 hash: 263d031d2c86858d0004cec1ea4b1b4d
humanhash: solar-zulu-neptune-spring
File name:Purchanse_order.zip
Download: download sample
Signature AgentTesla
File size:630'622 bytes
First seen:2020-08-31 10:46:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:hNOqzrnvZtkfYtgUyx6rK5fq5cMpdJ1Yv8YgNYl4/bPqfVrmLG:hNr7LPt2VhM3J1o/l2PoQG
TLSH 74D423E1D3B9026D3F8519F284054ADE71CC87F0AD2752B30E93E815F4BE48A596F6CA
Reporter abuse_ch
Tags:AgentTesla Hostwinds zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hwsrv-762686.hostwindsdns.com
Sending IP: 104.168.158.102
From: AL BADIA CEMENT <info@chenyuanglobal.com>
Subject: RFQ
Attachment: Purchanse_order.zip (contains "Purchanse_order.exe")

AgentTesla SMTP exfil server:
mail.gascuenca.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-31 03:04:36 UTC
AV detection:
8 of 47 (17.02%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip ceff414fdb663579196bea272215d1a62f84ea60ebe5da6d6b140b3de0dd9f39

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments