MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff6cd1970c39a9ac1e6ba8a9a3f8928096dd2cc4c1e2a9054537d8b5f0cd9d22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ff6cd1970c39a9ac1e6ba8a9a3f8928096dd2cc4c1e2a9054537d8b5f0cd9d22
SHA3-384 hash: 0ad7cee9f769c5bd36852d4a75d53d63b0e89f20999e20ae36b7c2b494bfd8fe49ecf8e873ce7744910369ccf7a1920a
SHA1 hash: 07561b30ee84c197b437cb42614bdd59fb56d471
MD5 hash: 5956284c32e65c8e0e5a3484fea11c50
humanhash: uncle-eleven-connecticut-nitrogen
File name:W04-BOD01.l.uue
Download: download sample
Signature AgentTesla
File size:1'023'359 bytes
First seen:2020-08-18 09:44:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:qcogz4sxGnJ4EDiE8gxf4UPN+b25AWC+U3e+5cF1TSA1BDrg+39:qopjgiWxf4UAKyWTU3e+54uSBDB39
TLSH 812533FAEEC56CC3AD8D61E0C416CCF5712EE56F1384A7414881CB61E842B6DBE26D93
Reporter abuse_ch
Tags:AgentTesla MailChannels uue


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: relay.mailchannels.net
Sending IP: 54.245.125.39
From: admin@co.id.nxcles.xyz
Subject: RE: PO W04-BOD01
Attachment: W04-BOD01.l.uue (contains "W04-BOD01.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-18 09:46:07 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip ff6cd1970c39a9ac1e6ba8a9a3f8928096dd2cc4c1e2a9054537d8b5f0cd9d22

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments