MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2376ae85656a05718dbe1e14af2ff67773fce73897be006fd33dc603b047e67e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2376ae85656a05718dbe1e14af2ff67773fce73897be006fd33dc603b047e67e
SHA3-384 hash: 7f006dfcd42a3552669e039524bdd4b932af32d2ee7b613d37087ad1a93706b3174f76fddf66d4e1b9f649e67d95e4f3
SHA1 hash: 3385f3ab8dc84bfac7453c07e1037a7da944885a
MD5 hash: e4b269b15ab671bf03004fa3482fab20
humanhash: angel-east-black-fillet
File name:Shipping documents.gz
Download: download sample
Signature AgentTesla
File size:425'884 bytes
First seen:2020-08-13 05:47:50 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:KjOebtVijI6CSb6sylsaytVtctlEU+SwZhqcd31:KjHtoCS+p5sSwZhqUF
TLSH 1F94236AC5B63BFFDB69840246A9542ED2474017B5B31A0DF0A94B3712B47FD1CCB523
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: centralandme.com
Sending IP: 185.222.57.238
From: Meryem <care@centralandme.com>
Subject: Re: Shipping Documents / Order 184559 SX
Attachment: Shipping documents.gz (contains "Shipping documents.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-13 03:10:53 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 2376ae85656a05718dbe1e14af2ff67773fce73897be006fd33dc603b047e67e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments