MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0261691c7595a0772741cccb067ae4c2facabef80eacc661e539b1457911121. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e0261691c7595a0772741cccb067ae4c2facabef80eacc661e539b1457911121
SHA3-384 hash: d583f2b9a682dbb6180b54d7c0b1786a9e99f54bcb5765b59976dec3b569506e20975275254c1face30c8fa39a845826
SHA1 hash: 66d448c94fbd32d38af0626ad28d12c63a24ffdf
MD5 hash: a7ed07f4d90b2aa1a4e754891329f6bf
humanhash: mango-twenty-april-don
File name:Quotation 78565.Scan.pdf.cab
Download: download sample
Signature AgentTesla
File size:412'981 bytes
First seen:2020-06-16 10:48:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:lfeXH1D2OeJtHqrDtqttsVU54e7J1smDIczZ:UYOeXH+DtqIVUGe7n9
TLSH 8A94233837C5CC21EE0E5C693DF28F9C4261B31BBAD7A918867A2C518B44469FBD418D
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mono.avnam.net
Sending IP: 190.210.186.210
From: SHF Trading Co.,Ltd <sales@atagroupuk.com>
Subject: New Order 042020
Attachment: Quotation 78565.Scan.pdf.cab (contains "Quotation 78565.Scan.pdf.exe")

AgentTesla SMTP exfil server:
mail.dehydratedoniongarlic.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-16 10:50:05 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e0261691c7595a0772741cccb067ae4c2facabef80eacc661e539b1457911121

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments