MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16c81eb7ab780d2e81af35f0387792ca5b0b423017ed3b8684c704fc88d25f05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 16c81eb7ab780d2e81af35f0387792ca5b0b423017ed3b8684c704fc88d25f05
SHA3-384 hash: 45c9bd9bc8c395b87a97d41c7346b64e5f3bd14ccb6a94fe66cbb183f02544d58c514c43f8b7c38661569bf6f4d65b0a
SHA1 hash: 1b60e89007c0fbc1545d29fffba2a84ef33a7849
MD5 hash: 34ed19c4a5938bef51e447000a528582
humanhash: may-yankee-ink-robin
File name:NaruÄ ite 0521360021.arj
Download: download sample
Signature AgentTesla
File size:422'033 bytes
First seen:2020-06-08 09:13:59 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:H0Sp1Ai/ci1WaxN2Bw90K9UHX0kkDrc4KhA:XFci1WQN2Bwqp3DkDrcy
TLSH 439423DA0671325149C68CDF271920A626CB26471BDD7FFA8E21080FD7B518E96E933F
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mxload.webglobe.sk
Sending IP: 212.57.32.37
From: Alen Geler <esivakova@mlproduktion.sk>
Subject: Naručite 0521360021
Attachment: NaruÄ ite 0521360021.arj (contains "NaruÄ ite 0521360021.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-08 09:15:08 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 16c81eb7ab780d2e81af35f0387792ca5b0b423017ed3b8684c704fc88d25f05

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments