MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f91e5b39c671f896a27a404179022eaf9822457320735374274de322ae6855fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f91e5b39c671f896a27a404179022eaf9822457320735374274de322ae6855fc
SHA3-384 hash: 0e63a5b0cd39ddbe966a770b7c143202aa2e1a4dfc8d30e0de929a85c71ebe32e086fe2262e616384b55bb869183bb3a
SHA1 hash: 48a32c3a15fa022f62ad1e457c290524f99587c7
MD5 hash: 0898fb14ed665020fdd567e764f9a371
humanhash: helium-cat-wisconsin-shade
File name:PO.4029530.zip
Download: download sample
Signature AgentTesla
File size:356'232 bytes
First seen:2020-05-08 08:53:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:xamAcp0GMcn61+KkBG+vhxTrR779JLCl4UatlmekccPWGVWQ2qHoi5:4epzMm61+fBXx/nJLCjaKeUPFVWQNHn5
TLSH 657423A91326ABD8F18B4D5FB13D858D8F47E6A5052A7628CBC4EEDCFC505B9061CCC8
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: safetysurveyors.com
Sending IP: 37.49.230.30
From: sales52@archantiquities.com
Subject: RE: quotation/offer (PO.4029530)
Attachment: PO.4029530.zip (contains "PO.4029530.exe")

AgentTesla SMTP exfil server:
smtp.bnb-spa.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-08 09:36:13 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f91e5b39c671f896a27a404179022eaf9822457320735374274de322ae6855fc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments