MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11464406915eec077965dd4d47c329c3cd04afb3d481f1e65766f9b60e030c47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 11464406915eec077965dd4d47c329c3cd04afb3d481f1e65766f9b60e030c47
SHA3-384 hash: f0e9e06b5fd6a96c8ad4754c7d46256afe32c543d3695437b5bf12783c24dccb4e37438b25a6aeb65c155b2997161722
SHA1 hash: 0eb8b663786525322bae9202743a72f3f216679f
MD5 hash: 986ecddda7eb06cea968cef511208543
humanhash: delaware-twelve-nebraska-east
File name:P160999.rar
Download: download sample
Signature AgentTesla
File size:508'343 bytes
First seen:2020-07-10 17:36:52 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:7rb+EmTrEQbj/cIR3US9vk+fsev5L0AguK2QGEw7tixk5:SoQX5N9V1v5PgjSixk5
TLSH 68B423E2D20D4767766D04683DEB561E235A3F08F52ABF0A4E5394E00B2FB99F748E41
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fax.local
Sending IP: 118.99.229.12
From: Chia Hui Trading Co <info@chia-hui.com.tw>
Subject: Proforma Invoice No. I180103-01
Attachment: P160999.rar (contains "P160999.exe")

AgentTesla SMTP exfil server:
smtp.epaindemgroup.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 11464406915eec077965dd4d47c329c3cd04afb3d481f1e65766f9b60e030c47

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments