MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1e2563d2937cee4e31f8988237c29dc36d3392b9392df0d87dd61bc5824c6753. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 1e2563d2937cee4e31f8988237c29dc36d3392b9392df0d87dd61bc5824c6753 |
|---|---|
| SHA3-384 hash: | f47a9ceb0e5862fcd9b7b9f2e566457025f80d3a7c7cd38975cee85263d5f5ab9b1963b1b47c76c8cfe3b08a5818c4a6 |
| SHA1 hash: | 512e059c1ab9e9daebb5bffa3e6227e371abbbaa |
| MD5 hash: | 718ac1057b7f260d8c4923ec7674bcfa |
| humanhash: | sierra-leopard-floor-mobile |
| File name: | VESSEL DETALS 2.7z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 507'006 bytes |
| First seen: | 2021-04-05 06:33:10 UTC |
| Last seen: | Never |
| File type: | 7z |
| MIME type: | application/x-7z-compressed |
| ssdeep | 12288:lowLc3iBu2mDKAPBgMOz0sFCGiMq21z9GLObNBBceI1Z:l6iBb8Jk1CUB99GISeCZ |
| TLSH | D1B423E1E494CC4A34DE9D51316020FABF79C3F8BB942533C8B9C685C9A3BC956A06DD |
| Reporter | |
| Tags: | 7z |
abuse_ch
Malspam distributing unidentified malware:HELO: slot0.altcbs.com
Sending IP: 185.121.120.159
From: SHENG LE C<shemglec@amosconnect.com>
Reply-To: shemglec@amosconnect.com
Subject: MV SHENG LE C//DISCH CARGO AT MOROWALI&KENDARI PORT,INDO
Attachment: VESSEL DETALS 2.7z (contains "s.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
207
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-04-05 06:34:29 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.35
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.