MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e8d418de2e2479f8264e5a05021a0dc804af5d5d2364ddbbaa0a3eec25853e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e8d418de2e2479f8264e5a05021a0dc804af5d5d2364ddbbaa0a3eec25853e6
SHA3-384 hash: 5ad82a1a54650487ab34650138d7814c34161c5de780b5784b9ee819b996c6cf530a48e098dbb2b2fe86e32867928eaa
SHA1 hash: fe3b7cf32e6ec0c323337a080aba44db359b895d
MD5 hash: 630ed98991573fff7beeb88741d20ad1
humanhash: nebraska-pennsylvania-neptune-leopard
File name:payment slip.r11
Download: download sample
Signature AgentTesla
File size:1'006'827 bytes
First seen:2020-06-11 05:47:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:WbUGmJplaYtE4QVRuNMSnaazUIyg77PDKpFR//ZRxOUTl7NI:WbUGApvmUatOgg777KpFR/RRxOO/I
TLSH 92253377E6B2286AD25A72BC06FF5F0571C353681DE24797B23BCC00907679B62C8D92
Reporter abuse_ch
Tags:AgentTesla r11 Yahoo


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic310-25.consmr.mail.ne1.yahoo.com
Sending IP: 66.163.186.206
From: Albert <kravitzlen@yahoo.com>
Reply-To: Albert <kravitzlen@yahoo.com>
Subject: Payment slip
Attachment: payment slip.r11 (contains "payment slip.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-11 05:49:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 0e8d418de2e2479f8264e5a05021a0dc804af5d5d2364ddbbaa0a3eec25853e6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments