MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea9f561f456f701ba4651db5d64290a7bdec93e3a6c5919c6047d171ea9d5858. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea9f561f456f701ba4651db5d64290a7bdec93e3a6c5919c6047d171ea9d5858
SHA3-384 hash: 1638886ee6289a949674711df92acf2859d524edcb39f0b51744b526867d455e1e686a674f5cc93369cc1df15aef10db
SHA1 hash: ce414cee51af8440e97cb46f743b9a085a5a4259
MD5 hash: 011c0f9334f9cc1ad9033242f3e05f34
humanhash: louisiana-skylark-freddie-virginia
File name:TNT SHIPPING DETAILS _PDF.rar
Download: download sample
Signature AgentTesla
File size:219'644 bytes
First seen:2020-07-10 07:42:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:DAit8asuNAnbPohW4j/SwzUdPwHiblKkA7u:DFjNAkg4j/kdeiblKkA7u
TLSH 792412F2508789771AC1A6CB46F9108847DA78732776C2097B4E77DB6387329B32F44A
Reporter abuse_ch
Tags:AgentTesla rar TNT


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.907.chenfeihong.casa
Sending IP: 68.183.92.100
From: TNT Express <service@tnt.com>
Subject: TNT Delivery Notification: Confirm your Current Shipping Address
Attachment: TNT SHIPPING DETAILS _PDF.rar (contains "TNT SHIPPING DETAILS _PDF.exe")

AgentTesla SMTP exfil server:
smtp.arrmet.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-10 07:44:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar ea9f561f456f701ba4651db5d64290a7bdec93e3a6c5919c6047d171ea9d5858

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments