MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb43407ee7ae51e81270d21db3c2bfb8a480281840bbf3cb212a4b7a51fa7d77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: eb43407ee7ae51e81270d21db3c2bfb8a480281840bbf3cb212a4b7a51fa7d77
SHA3-384 hash: 50c71e9eb05f50e4d86e86ae4b33cc533536d93fffab5d1fde105f8a8368b16e546d72c5a27ba4ce65b6a6ba9518c612
SHA1 hash: a50f71b72d43fd00cb0639daf57788810043d1be
MD5 hash: f31396003b7da26165bb3fb8fca2742d
humanhash: iowa-tennessee-sweet-nine
File name:PO209027_xlxs.gz
Download: download sample
Signature AgentTesla
File size:599'344 bytes
First seen:2020-08-31 08:54:03 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:2uLf3cTlaTK5i4tkUQHjQj8pUEDZHXEgiAN6t:2urd1kaDzUEDZUgVN2
TLSH B5D423AE1E388C820BF62EE55DF9F3230DD6E38696F3B39EC59051198BE455207D29D0
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: webmail.cyber.net.pk
Sending IP: 203.101.175.37
From: sales <amirn@cyber.net.pk>
Subject: Re: Re: PO#209027
Attachment: PO209027_xlxs.gz (contains "PO#209027_xlxs.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz eb43407ee7ae51e81270d21db3c2bfb8a480281840bbf3cb212a4b7a51fa7d77

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments