MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 103ddbecf62984789f874fb2d4ec846feeef6d40c191bc35285379a7c6d77228. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 103ddbecf62984789f874fb2d4ec846feeef6d40c191bc35285379a7c6d77228
SHA3-384 hash: 32eb65b59dec4ee816930c44f0aed61f581b8d2123ed64933042019587105459696fc784ab6ca3fc61bd0e5ef24cd8ae
SHA1 hash: dae418bbb418d0cf4b7488e8143afe52105cdf70
MD5 hash: 845f30f2eb3538e95b984784090ee1b1
humanhash: echo-early-william-video
File name:quote documents.rar
Download: download sample
Signature AgentTesla
File size:419'488 bytes
First seen:2020-06-08 12:22:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:gr8LXWPG+wYDt4XdSm/5veBKwzMgku5NG:08aPb3s7/58KXBuy
TLSH 549423A1FD65CB23892D0F259758460A76B4BE66343F4D0A2BADDF4B5C04CEE018B9F4
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: atosmedical.com
Sending IP: 209.58.149.114
From: "张伟Zhang Wei" <info@atosmedical.com>
Subject: QUOTE REQUEST
Attachment: quote documents.rar (contains "offer_pdf.bat")

AgentTesla SMTP exfil server:
smtp.mosaiclayouts.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Document-Word.Trojan.Powdow
Status:
Malicious
First seen:
2020-06-08 12:24:06 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 103ddbecf62984789f874fb2d4ec846feeef6d40c191bc35285379a7c6d77228

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments