MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f270c51a220d59d9fa899322c0e18f5b6331b5137c0cd967d7c3af39a1309310. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f270c51a220d59d9fa899322c0e18f5b6331b5137c0cd967d7c3af39a1309310
SHA3-384 hash: 35ffb8ec9928f9cb19ce95596629f715b32c175f6befe79ccd008e5c262f096beb124ab63fc4caa9d795c1d5e97dc5af
SHA1 hash: 4c5b9efbbf262de1c65bc736046b0c0c4387e813
MD5 hash: d78d94bb46e65a0e566daf0c50cb31f7
humanhash: west-earth-edward-mockingbird
File name:Order PO_06-15-2020.zip
Download: download sample
Signature AgentTesla
File size:443'626 bytes
First seen:2020-06-15 12:29:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:7gez70holnXPneQz0rMWpzKff9tr/fsbNiY3bT75ZwiZnka4e3u27WfvFAVUEWxW:7j0StXP4MGA9Bf3GTH/KXiQvFUUJW
TLSH 1A9423D46563E02DAF36CA9C737784F91AC2ABB70FF2C7F013543242499379E9619868
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.mokiastrade.com
Sending IP: 45.95.169.250
From: Christos Koutsioumbris <info@mokiastrade.com>
Subject: Πρ: RE: order Cyprus
Attachment: Order PO_06-15-2020.zip (contains "Purchase Order #PO_06-15-2020_08 49 54_00.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-06-15 08:32:18 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f270c51a220d59d9fa899322c0e18f5b6331b5137c0cd967d7c3af39a1309310

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments