MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2699649648ab67ed5aa9ba4899ea64c5ab5c42a498f7500c43639b1ebc25ef6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2699649648ab67ed5aa9ba4899ea64c5ab5c42a498f7500c43639b1ebc25ef6c
SHA3-384 hash: c31348af1ef05f09804f32f7574f40869251a48793a0ad2c28ae99905b1536a840c79ee231a904ba42354b9a97c71bd3
SHA1 hash: 4a17cfec09d36cd54dc47c4c699e77ebb55d1430
MD5 hash: ac1f4f819ad099a7c26f7298a77e1259
humanhash: ceiling-stairway-carpet-salami
File name:PROPERTY FOR SALE CYPRUS 300,000 EUROS.gz
Download: download sample
Signature AgentTesla
File size:617'130 bytes
First seen:2020-12-26 19:00:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:x+qEl2UEH4HxA0c0oQ3TECcqhwrhmMHq3IpwCciXy/JTzJU:x+qEl2TH3g5itdpwyiI
TLSH F2D4239176C8E1CF7CC21C278B5DDD91AAB80F093985BB3352580676D85DB8CAF4E4AC
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server0.gbfasthost.co.uk
Sending IP: 193.39.253.100
From: Realtorlansbreysales <sales1@reinvest.com.cy>
Subject: Property Details In Cyprus, Check pictures and Prices
Attachment: PROPERTY FOR SALE CYPRUS 300,000 EUROS.gz (contains "PROPERTY FOR SALE CYPRUS 300,000 EUROS.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
253
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-12-26 19:01:06 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2699649648ab67ed5aa9ba4899ea64c5ab5c42a498f7500c43639b1ebc25ef6c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments