MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 210238dbf03816848dae434a0181d6bf2a15ece57929ae767d2edfff994e7aae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 210238dbf03816848dae434a0181d6bf2a15ece57929ae767d2edfff994e7aae
SHA3-384 hash: 36f1988852e3f7a3d2a43bb9b94e5169f96e65c097891c5fb6df5732c5d6d68bf2b231677a839f723d0571b01efa5b06
SHA1 hash: 0d96befe6ed63dbaf9ed6ad68eba7db51cf33abb
MD5 hash: 3e825a08a33dc1381ae0671342f34d03
humanhash: nevada-seventeen-sad-kentucky
File name:PO-ORDER9801.gz
Download: download sample
Signature AgentTesla
File size:1'017'172 bytes
First seen:2020-06-10 15:37:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:qh2iqV/KmgMBWdR1dsTZRrc5PYznKAPzoecd:TiqFKmgMADkTrcymAtA
TLSH 1E253348547021B8765381A6204BECEAF6C77C5A39EC974B0C1FC3681FBE16F97199D8
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.strongmailvault.com
Sending IP: 111.90.144.228
From: Giulia Chan <office@jinpao.us>
Subject: TOP URGENT QUOTATION REQUEST ...RFQ
Attachment: PO-ORDER9801.gz (contains "PO-ORDER9801.exe")

AgentTesla SMTP exfil server:
smtp.cnlcherm.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.AitInject
Status:
Malicious
First seen:
2020-06-10 15:39:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 210238dbf03816848dae434a0181d6bf2a15ece57929ae767d2edfff994e7aae

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments