MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f701f96407bd457ac725156d49546ac4842edac44ee2d9357c0219d18ef1a85b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f701f96407bd457ac725156d49546ac4842edac44ee2d9357c0219d18ef1a85b
SHA3-384 hash: d07eb5e4d845413518b879a48a293aad14d01759db23a38df6d17cb5e4bf7ca19766b681317900212e1e00711c2fd3de
SHA1 hash: 321d72c140ec52c31bb980109232825679d14566
MD5 hash: 29a1cd94d22f3306c292c379d256608d
humanhash: video-cold-white-edward
File name:E20032.rar
Download: download sample
Signature AgentTesla
File size:422'063 bytes
First seen:2020-06-25 07:56:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:NtK1GTo8rJA416GsFc/KghAUGRq7j/slzpAYMKmbe1O:NgFAJY0Lh3kEj/slzqYMH
TLSH DD942333D799A38012BD1A3A522AEDFB2BFF06C2F483F574A7014414F1DA641A97675C
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.yuzhani-group.com
Sending IP: 45.95.169.107
From: Luca Favari <info@yuzhani-group.com>
Subject: ordine in sostituzione
Attachment: E20032.rar (contains "E#20032 ORDINE E-COMMERCE 212742 ROOSENDAAL 40 HCPW.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar f701f96407bd457ac725156d49546ac4842edac44ee2d9357c0219d18ef1a85b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments