MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e98a56fac35f692b1860f19b49e4dfc99a801baa0a8ee23e95182f240477943f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e98a56fac35f692b1860f19b49e4dfc99a801baa0a8ee23e95182f240477943f
SHA3-384 hash: 45424d95888815b4de0b0c2c57da3997d0e5e50ebb9a8af326df56fdafe7f96504e6452d5c7b4b1c334315a416f31e8c
SHA1 hash: f63300c10d5ede369e9ceb4a923927a3147859c8
MD5 hash: 421bd3c9d266b3d345085ab38f0b2bf8
humanhash: bakerloo-oven-whiskey-hot
File name:Swift LC_23032020.pdf.z
Download: download sample
Signature AgentTesla
File size:352'541 bytes
First seen:2020-06-25 13:13:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:d7oKjgtOOXhBGJDW2kOyo+nGeOeHS6CKriHYYEGDUumeI+KRYKMZwm:d7oK8oOHqqXOb+seHS6CMtYE5CgY75
TLSH C174238D27A22486BAC56C3C8C87E6A5162723ED91BD39C7B39935ED050F0FF7888509
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: masegulf.com
Sending IP: 156.96.62.208
From: k.alhariri@masegulf.com
Subject: LC swift
Attachment: Swift LC_23032020.pdf.z (contains "Swift LC_23032020.pdf.exe")

AgentTesla SMTP exfil server:
mail.bestinjectionmachines.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-25 13:38:04 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e98a56fac35f692b1860f19b49e4dfc99a801baa0a8ee23e95182f240477943f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments