MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16e6d3573c9d2baff23f67eebd2cf90c3755023f3f03efb300fd0eeb5a282d7e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 16e6d3573c9d2baff23f67eebd2cf90c3755023f3f03efb300fd0eeb5a282d7e
SHA3-384 hash: 92c513975de2dfb5af23a50ee9d585b191ee84bbd78eb100c1d9136ebe206ec658df3e8ef87ef76b8c93f0360a574811
SHA1 hash: fa6e3b318239d4a8e579de9fc6d1ad916bf2440c
MD5 hash: 385e8870690a28b6253b3376e48b7476
humanhash: fruit-cardinal-enemy-echo
File name:PI-CP200213001-BR-PAK-Wire Bender CHR-08-3A UR130 for Canwin.zip
Download: download sample
Signature AgentTesla
File size:371'042 bytes
First seen:2020-06-23 05:54:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:htJv4v9cOR6fCyk2JhQ+fco38ia4vLR+q5NeqoSDUBmhgnOjc8qQGAGAta0dcGPm:EeORQCWQAnta4AwUBIeO48wAhdcGxc
TLSH D78423E4728B67B5C5BAA2754DA7C9B42AD87ADCF5EA0003F4EA77720CCE041B5D8910
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.btjlines.com
Sending IP: 137.59.125.189
From: brian.lu <brian.lu@ylm.com.tw>
Subject: Re: requirement for wire bending machine
Attachment: PI-CP200213001-BR-PAK-Wire Bender CHR-08-3A UR130 for Canwin.zip (contains "PI-CP200213001-BR-PAK-Wire Bender CHR-08-3A UR130 for (Canwin).exe")

AgentTesla SMTP exfil server:
smtp.israelagroconsultant.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-23 05:56:06 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 16e6d3573c9d2baff23f67eebd2cf90c3755023f3f03efb300fd0eeb5a282d7e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments