MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1489694b5b16a1bb1a0188322b1b41e9684925fe2a2862bbf4a5fe8d7961573. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f1489694b5b16a1bb1a0188322b1b41e9684925fe2a2862bbf4a5fe8d7961573
SHA3-384 hash: 95542b3cb2280b8037b097b4bd9ae4a16011ef6530ec8041e4f60d369d6f5057f9de83c6ace31b138e985ca075e3a495
SHA1 hash: f5d5b145b81c1bdc158f89deaaffd933524dbb9a
MD5 hash: 4b7821f94367782eeff85c8006aaf796
humanhash: solar-princess-delta-ink
File name:End-User Shipment Docs_Eval-MV-MARY0001983999190.r00
Download: download sample
Signature AgentTesla
File size:919'708 bytes
First seen:2020-06-16 06:13:37 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:J5Fz3l1c2hVxPlaVeJVpJrW/3XcE+hneE48FUeK:J5r1fhDeeJVpJ+yneE4iVK
TLSH 741533809897AFCE675748098F72867891AC0CCE53A8F14F455A8C4953FF23FAD280DB
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.anchinfotech.com
Sending IP: 192.163.233.90
From: Mark E. Ocampo <import@tici.com.ph>
Subject: RE: AW: TH MARTIN 2486 MV Grace Previous shipment Documents / Arrival Notify
Attachment: End-User Shipment Docs_Eval-MV-MARY0001983999190.r00 (contains "End-User Shipment Docs_Eval-MV-MARY#0001983999190.exe")

AgentTesla SMTP exfil server:
mail.gcs.co.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.AitInject
Status:
Malicious
First seen:
2020-06-16 06:15:12 UTC
AV detection:
34 of 47 (72.34%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 f1489694b5b16a1bb1a0188322b1b41e9684925fe2a2862bbf4a5fe8d7961573

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments