MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3e119239e5349c2bdf851fbd93072b3bac590158a6ca64d233979fece26c01e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e3e119239e5349c2bdf851fbd93072b3bac590158a6ca64d233979fece26c01e
SHA3-384 hash: 4c8b1ef44a7ba18c31354f395739d33a1acfa1c9d5a7cd7bf1299a9873ab5038a65dd93521465b4eed9dbf6044fe7956
SHA1 hash: 567d4f9bf51325b6f3af31783a57119e90a5c69c
MD5 hash: ebe7c8abb9a2952298b00b53d2b6a0a8
humanhash: low-sink-winter-papa
File name:PRICE REQUEST.zip
Download: download sample
Signature AgentTesla
File size:391'189 bytes
First seen:2020-06-26 11:54:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:LAaUCRtQ0VLFA/GhjvNl0ykG8rm1FnajkgOnJc9MnoC+VXqob6qIbLl7amDR4BMb:LAX0VwGhLNl0yRa8ckg1Molcob6ZbL9X
TLSH 2D8423C9AE9DE1B1B45E09D6C67EB31958B5FDB23391B0022F3F40111031ADEACE695B
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: www2.webmail.pair.com
Sending IP: 66.39.3.96
From: Hamza Khan <import.khi@aliyaz.com>
Subject: PRICE REQUEST
Attachment: PRICE REQUEST.zip (contains "PRICE REQUEST.exe")

AgentTesla SMTP exfil server:
smtp.bnb-spa.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-26 11:56:05 UTC
AV detection:
21 of 28 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e3e119239e5349c2bdf851fbd93072b3bac590158a6ca64d233979fece26c01e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments