MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6a628fe234851cb3045421c715d20564d6838deeaa36385289e670e85f26daf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d6a628fe234851cb3045421c715d20564d6838deeaa36385289e670e85f26daf
SHA3-384 hash: a96607dba2c5651ed45075d71e2d94bce7bd9f7200dbc324d3f782ef4b7e7d1cc72a97884b3d6c4fc1767f9668158506
SHA1 hash: 35a0320aea5895e905961e1449eac1d76f2ef885
MD5 hash: 24d0e492ec508f017e50ca44c50fd437
humanhash: grey-kilo-juliet-jig
File name:News-Update.zip
Download: download sample
Signature AgentTesla
File size:395'494 bytes
First seen:2020-07-16 06:59:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Fr+VF02kLMjzxW2FwAUgzWgneDl4Xq/PRDG6YkkJKngbSGR5NUCmOOGTbwg:9ECh0W2FRp/eDOwYX9bVbNU1HGTbwg
TLSH 4884238C6BF0E17390B28577D0552FDCFA2B9BD1335B7D1ABB25981E288E1F19172848
Reporter abuse_ch
Tags:AgentTesla Endurance zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 192-254-193-67.unifiedlayer.com
Sending IP: 192.254.193.67
From: Thai Rice Exporters <contact@thairiceexporters.or.th>
Subject: Update Rice news for 16 Jul 2020
Attachment: News-Update.zip (contains "News-Update.scr")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 07:01:05 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d6a628fe234851cb3045421c715d20564d6838deeaa36385289e670e85f26daf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments