MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e21ee8516cb2fdf009d7b783cfee05118090f8642d02a5ba0587d6a2bad37ad0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e21ee8516cb2fdf009d7b783cfee05118090f8642d02a5ba0587d6a2bad37ad0
SHA3-384 hash: 9fcf25ecb8b2afcfc3e9a23fc6aebbb704656e849b1e034a73a5f903cfcda1cc1d0a1df436307a091d184eb24ccb95b6
SHA1 hash: 67c346dc001f579921d6c9d63536ce3ec59cb929
MD5 hash: 7b453b39d2005fea6946b3ce4ef02159
humanhash: music-three-romeo-double
File name:SUNCOAST-PO-02-08-2020.eml.mail.zip
Download: download sample
Signature AgentTesla
File size:482'252 bytes
First seen:2020-08-02 11:55:49 UTC
Last seen:2020-08-02 17:13:29 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:5cPDdIXOHw/q9YjQNaB82wgNQgpzZiisPRQh2heRtOIHxPaxjk:5cPqZLjQ2bN3pduQhyAtOQxSxjk
TLSH 29A423222FFE23A9B93602191030ED7658D096DB6D57DC67669467AE728EC6D3C3FC00
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: suncoastmarketing.com
Sending IP: 23.159.176.84
From: Silvia Brull <purchases@suncoastmarketing.com>
Reply-To: Silvia Brull <purchases@suncoastmarketing.com>
Subject: FW: Purchase order
Attachment: SUNCOAST-PO-02-08-2020.eml.mail.zip (contains "SUNCOAST-PO-02-08-2020.eml.mail.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
5
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e21ee8516cb2fdf009d7b783cfee05118090f8642d02a5ba0587d6a2bad37ad0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments