MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e94b3f202e95e5193960999602cfd57e8f62ca7a45ff4cb1f7113e18e541b6ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e94b3f202e95e5193960999602cfd57e8f62ca7a45ff4cb1f7113e18e541b6ab
SHA3-384 hash: 9cccd5389aa24a04ce13b0fcc4ae1102c2bb03802b883803828adc0f4c82334e3443a5c7fe72fa1519da0c5cd9e3dc3c
SHA1 hash: 3b549c5996e24f1d1356aa7ac4c4fb982d1699b2
MD5 hash: 7cc990352a89b2f65e6fdf4234a70d99
humanhash: wyoming-december-bravo-lima
File name:MS2347 8000 sets.zip
Download: download sample
Signature AgentTesla
File size:438'229 bytes
First seen:2020-07-09 14:33:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:FyPsnOoDr96OvCUedR3zfv+ksUppqBDU5BRbL:8sJMECV3jmqk4xL
TLSH 3F9423C3AD1C74FE2073B0D5016498EFBCE14E09326A960646F1637B8B6B511CEADF61
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gomailbizbulk.life
Sending IP: 38.68.48.226
From: ZHEJIANG HUANGYAN SHENZHOU ARTWARE FACTORY<sales@gomailbizbulk.life>
Subject: 訂單 for MS2347 8000 sets
Attachment: MS2347 8000 sets.zip (contains "order1.exe")

AgentTesla SMTP exfil server:
mail.cjcurrent.com:26

AgentTesla SMTP exfil email address:
godie@cjcurrent.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-07-09 10:38:02 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e94b3f202e95e5193960999602cfd57e8f62ca7a45ff4cb1f7113e18e541b6ab

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments