MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e31dbcc5e9bfa5ed5c0377495f61a74ff25197e53faa36911cf89f9dd0e7472c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e31dbcc5e9bfa5ed5c0377495f61a74ff25197e53faa36911cf89f9dd0e7472c
SHA3-384 hash: 964f9fe952f219bc4adc50a551e50b16ec12afce9df72af0932be28425e0054a22ecb7d11b59cc8354d6d660e2f93c13
SHA1 hash: ed0b4f41a8931790a335e3429bf24db236bced45
MD5 hash: ab0ba5b96daeef64fbeb5d5bccc7a80e
humanhash: network-quiet-twenty-robert
File name:E20201-175467.z
Download: download sample
Signature AgentTesla
File size:425'775 bytes
First seen:2020-05-14 07:08:00 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:XGidqLYFsBHC4pc7iTmXrke3aCJKyqOEi5k35JtM1xGu:XGi7sBHC4pQX330Oh5G5zM1x
TLSH E094235A08DA739EC4B2BDB95DC327FB33806805D5A914633A0019D3FA5D7B7F88921B
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server0.aratirma.com
Sending IP: 104.168.136.3
From: Angela, Yang <sales@aratirma.com>
Subject: order 175467
Attachment: E20201-175467.z (contains "E20201-175467.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-14 07:37:04 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z e31dbcc5e9bfa5ed5c0377495f61a74ff25197e53faa36911cf89f9dd0e7472c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments