MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2376ae85656a05718dbe1e14af2ff67773fce73897be006fd33dc603b047e67e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 2376ae85656a05718dbe1e14af2ff67773fce73897be006fd33dc603b047e67e |
|---|---|
| SHA3-384 hash: | 7f006dfcd42a3552669e039524bdd4b932af32d2ee7b613d37087ad1a93706b3174f76fddf66d4e1b9f649e67d95e4f3 |
| SHA1 hash: | 3385f3ab8dc84bfac7453c07e1037a7da944885a |
| MD5 hash: | e4b269b15ab671bf03004fa3482fab20 |
| humanhash: | angel-east-black-fillet |
| File name: | Shipping documents.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 425'884 bytes |
| First seen: | 2020-08-13 05:47:50 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 12288:KjOebtVijI6CSb6sylsaytVtctlEU+SwZhqcd31:KjHtoCS+p5sSwZhqUF |
| TLSH | 1F94236AC5B63BFFDB69840246A9542ED2474017B5B31A0DF0A94B3712B47FD1CCB523 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: centralandme.com
Sending IP: 185.222.57.238
From: Meryem <care@centralandme.com>
Subject: Re: Shipping Documents / Order 184559 SX
Attachment: Shipping documents.gz (contains "Shipping documents.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-13 03:10:53 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.