MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d05671abb7e430ab9567881b11ff4dbfab4d9675e5ecb8128608d1d147b5c073. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d05671abb7e430ab9567881b11ff4dbfab4d9675e5ecb8128608d1d147b5c073
SHA3-384 hash: ff874cc2104b12614dd4dedfc5774c23fa3a1c8ac9f3f4cfbbd2deba9dedc5258f1182d1c7aa8edd57e611b6792b05d0
SHA1 hash: 7b19de5d14c1a4b7378b55643d3096b7a6254c26
MD5 hash: 03ccf85e781af6285154fb2b5ceec8ea
humanhash: mountain-louisiana-oranges-south
File name:ORDER.docs.rar
Download: download sample
Signature AgentTesla
File size:413'185 bytes
First seen:2020-06-24 06:36:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:j//XxOy70RMsljcDFedGV3YfdgbowN26J6Gg379h4/ot56M/IccuRNMRAraMt7+g:j//hqZ6DFeUYfI26JArs2khaNHSbTFO
TLSH C09423A4ED7DAEF18702D6661ACBAD1BE343B6BFB907D2E041514F3BAC79501011E1CA
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: lexia.it
Sending IP: 103.99.1.145
From: Kabri Hilgers<milano@lexia.it>
Subject: RE: RE: ORDER
Attachment: ORDER.docs.rar (contains "ORDER.docs.exe")

AgentTesla SMTP exfil server:
mail.pro-powersourcing.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-24 06:38:05 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d05671abb7e430ab9567881b11ff4dbfab4d9675e5ecb8128608d1d147b5c073

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments