MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a695ea2e5ca4bf9b3d7d9dd456ac03ca74d0c0eff9edfd5962b1a4bf4c2c993. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a695ea2e5ca4bf9b3d7d9dd456ac03ca74d0c0eff9edfd5962b1a4bf4c2c993
SHA3-384 hash: f868f5cdf14e874613618dc03b91aac8e81508d1efa71498a311715ce178e76367905124d204e78e30b056745c199aa3
SHA1 hash: 3d1d15ed615ef9abecb6d50ae355ec89e5535102
MD5 hash: f70201488baf7d4733671683f1b69a84
humanhash: alanine-princess-march-magnesium
File name:new order.gz
Download: download sample
Signature AgentTesla
File size:431'198 bytes
First seen:2020-07-07 12:33:39 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:+JTFyAHwUfcIQB2QsjP0XUlAhsA8sOrzUBLfUotMF7j/VyBSKGG:sr3cIQB2YXkAIQYcYw
TLSH 9394239510768AC0E065F92EBB7EDD8966E70C299C7C2C8033A4F6C4EFBD564C536368
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mekseaconnection.com
Sending IP: 95.211.208.25
From: Mekong Seafood - Jimmy Vong <sales9@mekseaconnection.com>
Subject: Re: 转发: new order
Attachment: new order.gz (contains "new order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-07 12:35:06 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 0a695ea2e5ca4bf9b3d7d9dd456ac03ca74d0c0eff9edfd5962b1a4bf4c2c993

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments