MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 df2d89c4ee883a801047341e14454970f7c2b96a5581cb2518df713d15948e74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | df2d89c4ee883a801047341e14454970f7c2b96a5581cb2518df713d15948e74 |
|---|---|
| SHA3-384 hash: | 5229d63fe43b312150ceafe151fcedbe3d98aa62ad6420700ed4de17c7779ec79f1a6d94d94c8b8bdce9c3bf6a4c0153 |
| SHA1 hash: | a0b38c3bd85dde368d90af4126824a10d96dd3c3 |
| MD5 hash: | 8c2596b8ed957faadf971707d817d443 |
| humanhash: | india-beryllium-tennis-virginia |
| File name: | P.I Officewears 28.07.2020.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 158'441 bytes |
| First seen: | 2020-07-28 13:10:00 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 3072:2jql8vcXP8YIMqeP7V5EpUc8Aw/74gclm21NrOGlq46so63U6mbMg/Qwi9J:szcXgyTH2ceNr56so63UN/dK |
| TLSH | FEF312AC7BBF5516F42BCE04A2527109EFCD90B38846957A180D11DBB8DD9AF8C71718 |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: server.example.com
Sending IP: 103.147.184.169
From: Jason Bourne <admin@beoxies.ml>
Subject: 回复: 回复: Revised P.I Officewears 28-07-2020
Attachment: P.I Officewears 28.07.2020.rar (contains "P.I Officewears 28.07.2020.exe")
AgentTesla SMTP exfil server:
smtp.office365.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-28 13:11:08 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.