MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1457014295e21581b8573689ff5ac29a8e1a1b9f914f3f50481ed503fd2d2b53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1457014295e21581b8573689ff5ac29a8e1a1b9f914f3f50481ed503fd2d2b53
SHA3-384 hash: db1219472e4c6118733a129b27c32a4299c94a0cc147a4795351a3e1bad1b11361ba5dd9f3ef94e6ec689b4da11ab46d
SHA1 hash: 8aecf309ee7f8f0f00125f39181d9c4764a49251
MD5 hash: 45e6febe6d9f83517936cc3579bb45d6
humanhash: twenty-pasta-october-cola
File name:DES_ Holdings Ltd - products list.7z
Download: download sample
Signature AgentTesla
File size:630'169 bytes
First seen:2021-01-06 08:00:07 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:n/ZEk6cEGtGItz3XrpaexO7HPRB8EGZsdkPc8xaZvaxVWx1v8lysWRnQjMwaq:+4EGtd1laex23zGZ8kE8xNQxsGQgwt
TLSH 41D43386CECAB030A502DBF2C0ACC56FA66360EAD1BF7CD48B369D54D9392F610495F4
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: srv.kibriswebhizmetleri.com
Sending IP: 213.159.5.123
From: DESIGNATED HOLDINGS LTD <info@inndormcyprus.com>
Subject: Request for Quotation
Attachment: DES_ Holdings Ltd - products list.7z (contains "DES_ Holdings Ltd - products list.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-06 08:01:11 UTC
AV detection:
4 of 44 (9.09%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 1457014295e21581b8573689ff5ac29a8e1a1b9f914f3f50481ed503fd2d2b53

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments