MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e5782f3b98860dedcbb1a885dbcbbad66e44c9c59c0a63ccce2f4afd95fd6ff7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | e5782f3b98860dedcbb1a885dbcbbad66e44c9c59c0a63ccce2f4afd95fd6ff7 |
|---|---|
| SHA3-384 hash: | 85fbdb5ad6f2f0a367be1968cdf0c1e64a312ea6f60f9c73e9c3827157f75836a9c04938a650a001d08105fb2d5e693c |
| SHA1 hash: | 2013f56a982dd44f7462168ce7e0ae86fc232417 |
| MD5 hash: | 6ef801e57eacf5c316383d247391deef |
| humanhash: | lemon-comet-carbon-oranges |
| File name: | PURCHASE-ORDER00233.GZ |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 282'715 bytes |
| First seen: | 2020-07-22 10:05:31 UTC |
| Last seen: | 2020-07-23 15:39:47 UTC |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:/1Q/eI/br5q9GWfmXCz2hLx7qwh8pJ+83uJjGdbw3b4PCeNaD6febx9Ddhq8b04:CeI/brDCmSKpx7qM828aCg4qexfezdvZ |
| TLSH | EB5423A066CF49CAEDC593B78E223E6FB34DCD68B5B92941B1B0F566E0140D315EF058 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.jmhkui.xyz
Sending IP: 176.119.30.85
From: Atabak Fekri <info@jmhkui.xyz>
Reply-To: sandra@mould-eliten.com
Subject: Purchase Order
Attachment: PURCHASE-ORDER00233.GZ (contains "PURCHASE-ORDER00233.exe")
AgentTesla SMTP exfil server:
smtp.yltab.com:587
Intelligence
File Origin
# of uploads :
2
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-22 10:07:07 UTC
AV detection:
21 of 28 (75.00%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Unknown
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.