MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8be2c2928299465a0bbb04c66acca713a6d52f1c11dda8318482f37acf99f5f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d8be2c2928299465a0bbb04c66acca713a6d52f1c11dda8318482f37acf99f5f
SHA3-384 hash: 9d6118e9f2b44b0b2fd061aae631434f7744cb0e1d5f6b5cbf2b162f09e744e9379e4bf42665f64409578d219e26f100
SHA1 hash: c7cbc193d0268896e4065c55ddcb477551a8c9fe
MD5 hash: 2771424e883bf1ac96e1bc4c777e9e19
humanhash: moon-music-kilo-texas
File name:sheet56734600.email.eml.zip
Download: download sample
Signature AgentTesla
File size:394'979 bytes
First seen:2020-07-24 05:44:11 UTC
Last seen:2020-08-01 10:00:32 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:U5fvs3V3Rf+cgMy2bl2a1UaBaFlp1LYNe:WfvSV3UkyLSUaCn1LY0
TLSH 0C842378F978369F1A0BC6BE9A59FF905DA2607042B70343E5EA2033E04835537598EE
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sgk-klenke.de
Sending IP: 209.58.149.66
From: Herbert Markowitsch <marko.witsrch@sgk-klenke.de>
Subject: Inquiry
Attachment: sheet56734600.email.eml.zip (contains "sheet#56734600.email.eml.exe")

AgentTesla SMTP exfil server:
mail.ibc.by:587

AgentTesla SMTP exfil email address:
greenpark@ibc.by

Intelligence


File Origin
# of uploads :
33
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-24 05:23:32 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d8be2c2928299465a0bbb04c66acca713a6d52f1c11dda8318482f37acf99f5f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments