MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dddc240a588d77462067fbfbed3bdb88e6f2412935b5c44e18c8d2bd45b388b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dddc240a588d77462067fbfbed3bdb88e6f2412935b5c44e18c8d2bd45b388b0
SHA3-384 hash: 393d49d48281f18b5fce7cb15fd6b9e24069574203256651cbb377d22d9fa8bc1be017d7a3ba4c2c598e689dbef6a555
SHA1 hash: c10c4b967579cbc8e65aa06efff0baea3c2afdda
MD5 hash: 29932611a22d02f8ff56021a10d5152e
humanhash: snake-seven-lamp-kilo
File name:New order 0020123.zip
Download: download sample
Signature AgentTesla
File size:1'083'210 bytes
First seen:2020-05-11 14:41:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:qmBzDChC8gDHVnq0epiIXAK4NqIHB7pc4JXsWLHsaKRoAoy+cNrRdN:qMDChC5AHVeNPx7JdbuocPj
TLSH AA35339DA29DB2609A5F92ED9743A139FDC61FBA14BCA212BC42541F05CFC76CF02C25
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: thermocool.co.ug
Sending IP: 70.35.202.75
From: Sankho Kaihatsu Co., Ltd. <donatella@fabiorusconi.it>
Reply-To: morischang@outlook.com
Subject: Re:Re:Re:Re:Re:New order #0020123
Attachment: New order 0020123.zip (contains "New order #0020123.exe")

AgentTesla SMTP exfil server:
mail.elkat.com.my:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-12 04:26:52 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip dddc240a588d77462067fbfbed3bdb88e6f2412935b5c44e18c8d2bd45b388b0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments