MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ffd3cc8c5628fff810737b47b2788735af8281dd86c2a6b1695868cfc53eae2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0ffd3cc8c5628fff810737b47b2788735af8281dd86c2a6b1695868cfc53eae2
SHA3-384 hash: 61fcb8bcb7d7861e76cc7544c40f85f9fbcaaf571a410121197d56413aac23f1e58030b7c15ffb3cfd1b464884b58c92
SHA1 hash: a7ea762d33da3cd643baece6e3ba0613b82905be
MD5 hash: 8dc1ab771df2b456ff61bf94c51932fd
humanhash: speaker-ohio-illinois-cup
File name:Purchase Sheet 2020.GZ
Download: download sample
Signature AgentTesla
File size:505'266 bytes
First seen:2020-05-09 08:23:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:YVMjC7kQfsf/yr4Neh07qeLTIE/oRLRZJu/GYUE6AZCj:YCv4trkeh07qeHqdRZU/GYUnAi
TLSH A7B4239CA8FF12E66FF4D51D7F9370A1F08E69883094D35C99807072E98761B2D39B68
Reporter abuse_ch
Tags:AgentTesla gz Yahoo


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic304-25.consmr.mail.gq1.yahoo.com
Sending IP: 98.137.68.206
From: Kum Wai Leng <waileng.kum@huationg.com.au.ms>
Subject: Purchase Sheet 2020
Attachment: Purchase Sheet 2020.GZ (contains "Purchase Sheet 2020.exe")

AgentTesla SMTP exfil server:
smtp.mail.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-09 08:35:28 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0ffd3cc8c5628fff810737b47b2788735af8281dd86c2a6b1695868cfc53eae2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments