MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5848676dd51c3b3f8c11220e073f62eebef1b25f148cfc75b73827bbabe003a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d5848676dd51c3b3f8c11220e073f62eebef1b25f148cfc75b73827bbabe003a
SHA3-384 hash: 24117f224d9e199e0cb5a2f71c3e0119d734099b8cdb6dc72c553cfe6462523d4a6951036a108568173bc9d86ecac778
SHA1 hash: 12889e30e947a554b8ae29426e4991276368c530
MD5 hash: 3d8a5a1ee41e686861444b5f58d1c3d6
humanhash: high-equal-minnesota-violet
File name:NEW ORDER.r00
Download: download sample
Signature AgentTesla
File size:999'025 bytes
First seen:2020-06-02 07:46:25 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:xuY+Le87CtQo4Mj3tT2tly+9BaIE+SymEFvYwVpXyDFu30On:xuY+aEW4mp2m+9VEjEFvYwShuko
TLSH D7253376FCAED7DCAB936B90CEA4A690088E9C096CC75A452F0AD4FC74C517D4148B3B
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mokitens.cf
Sending IP: 95.217.220.101
From: Jason Bourne <admin@mokitens.cf>
Subject: NEW ORDER
Attachment: NEW ORDER.r00 (contains "NEW ORDER.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 08:36:41 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 d5848676dd51c3b3f8c11220e073f62eebef1b25f148cfc75b73827bbabe003a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments