MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b5db82f902d10ad224e6c9bcbc2fa5cf04ca57dae580fa4215f765f89405f2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0b5db82f902d10ad224e6c9bcbc2fa5cf04ca57dae580fa4215f765f89405f2e
SHA3-384 hash: 22f5ecd58a497bb1a1f3b16fbd7250cc9e664f5d679270a254f80a968905476aed377db03f4f701a0d519d630ffdcd8a
SHA1 hash: ad311f258c3e78f2fbd0aa4b40c7c4dcfae4da50
MD5 hash: 643093848f48e93102709fba9eae5b2b
humanhash: september-don-echo-violet
File name:PO No. 104393019_pdf.gz
Download: download sample
Signature AgentTesla
File size:466'238 bytes
First seen:2020-06-02 06:56:01 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:Hms8y3YK+JxqnnCpOacvU+dOJmE3RI8MwnU+N6:Hm63Y1LqljvFNA69wng
TLSH 6AA42380C57F762CB6BA0B686AA85517D70711A28BD84C3237D0355DDEC2AF2389FB4C
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.vinylbannersprinting.co.uk
Sending IP: 217.174.249.10
From: Bahr Muhammad <info@albahralarabi.com>
Subject: URGENT PURCHASE ORDER No. 959309292
Attachment: PO No. 104393019_pdf.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 03:04:00 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 0b5db82f902d10ad224e6c9bcbc2fa5cf04ca57dae580fa4215f765f89405f2e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments