MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f514ca4174311af659a13deb2458f7b8b1f0ca524153bb825e98d2012bfe0fb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f514ca4174311af659a13deb2458f7b8b1f0ca524153bb825e98d2012bfe0fb6
SHA3-384 hash: f6ab9994356653d328744ae161155c530ecc5981e99aa7b93f325923dea632281b684c4d2d6380d0af3a74d87e025eb7
SHA1 hash: 01d683d27cb1a6e69fc05ea90816fc6ef04842f8
MD5 hash: d2a117b027d1134811a5a1b2fcbf99b9
humanhash: seventeen-butter-west-lima
File name:Doc_SubC-R0004.CAB
Download: download sample
Signature AgentTesla
File size:220'711 bytes
First seen:2020-06-28 07:55:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:+HM5I2qORkknbtrZ00LzNlseZJoVzKYjJuTubg:c1KRkknBrZ3zNCIYfLg
TLSH 4924239D807D9F15EDA4BA72994095C2B320FDA313E80BBC77E0ED41DD98062D39439B
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.rebelliongate.xyz
Sending IP: 45.95.169.223
From: Customs Finance Department<noreply@dubaicustoms.ae>
Subject: Document Submission Notification - 28-06-2020
Attachment: Doc_SubC-R0004.CAB (contains "Doc_Sub(C-R0004).exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f514ca4174311af659a13deb2458f7b8b1f0ca524153bb825e98d2012bfe0fb6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments