MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e643a127fdcae3f0ada30f6448e0db52e1220b591da686d5b6895e5a26c1efa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e643a127fdcae3f0ada30f6448e0db52e1220b591da686d5b6895e5a26c1efa
SHA3-384 hash: dfd71201ace116c5386aca21ff26becef6529f49fce7681823d6ab79d677dc99ea45872b3a10c839d6805e5db9fb08e1
SHA1 hash: 7d379cebe5cab6a8a8a8a78f8b2891c5726645bf
MD5 hash: 6146ab2e2854342da1d82704c5821515
humanhash: kentucky-indigo-uniform-jersey
File name:PO.zip
Download: download sample
Signature AgentTesla
File size:652'752 bytes
First seen:2020-07-09 07:34:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:gMz8ta74RlBQw5lKpq+p1pr+/KAPBqtsEdVaEuEPI9bNGJ4B3DSba:eta74RguKpj1Y/K+AtHnNHco27
TLSH 16D4239AE3110FC5E78C932B079FD08528D38D4F927B7B8A4D913D69DB092D634A62C7
Reporter abuse_ch
Tags:AgentTesla CVE-2017-11882 zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: somaci.com
Sending IP: 103.140.250.133
From: NOOR TEXTILE MILLS LTD.<Noortext.mills@hotmail.com>
Reply-To: Noortext.mills@hotmail.com
Subject: New Po
Attachment: PO.zip (contains "NEW PO.exe")

AgentTesla SMTP exfil server:
mail.cka.com.sg:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Document-Office.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2020-07-09 07:36:10 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0e643a127fdcae3f0ada30f6448e0db52e1220b591da686d5b6895e5a26c1efa

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments