MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e97398d69c45a4689f5515450a7a5b362c0beb742651f88aae0bd95df6a9da7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e97398d69c45a4689f5515450a7a5b362c0beb742651f88aae0bd95df6a9da7d
SHA3-384 hash: bc79a912ef363455395bc761ee7ad6d8c17c02346355f484cdca525dcd7d5a3fb9ef5e265683b7c5f6f50e9678e788ff
SHA1 hash: be656cd6f03d27806f9cdb82b961a6d813d38e91
MD5 hash: d6f59be4cac2c4f9ac103d8480adf6d6
humanhash: september-may-rugby-tango
File name:PO 45-1982020.rar
Download: download sample
Signature AgentTesla
File size:1'612'986 bytes
First seen:2020-08-19 14:08:00 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:0q9B0FgmItAkCZ9Xk/Plzrq8vuRjhUApWFdpscs4EOfivXBzsr7Da2:0smgmItAkWXiPteRjhXpW19EOa5A3Da2
TLSH 3C753344620F24848FB2CD50F61202C975B0176B98129B89EACBEF594B5F2FB67DF532
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cloudhost-357400.us-midwest-1.nxcli.net
Sending IP: 104.207.254.169
From: TIAN <career@elitegsl.com>
Subject: PO 45-19082020
Attachment: PO 45-1982020.rar (contains "PO 45-1982020,pdf.scr")

AgentTesla SMTP exfil server:
smtp.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-19 14:09:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar e97398d69c45a4689f5515450a7a5b362c0beb742651f88aae0bd95df6a9da7d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments