MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2699649648ab67ed5aa9ba4899ea64c5ab5c42a498f7500c43639b1ebc25ef6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 2699649648ab67ed5aa9ba4899ea64c5ab5c42a498f7500c43639b1ebc25ef6c |
|---|---|
| SHA3-384 hash: | c31348af1ef05f09804f32f7574f40869251a48793a0ad2c28ae99905b1536a840c79ee231a904ba42354b9a97c71bd3 |
| SHA1 hash: | 4a17cfec09d36cd54dc47c4c699e77ebb55d1430 |
| MD5 hash: | ac1f4f819ad099a7c26f7298a77e1259 |
| humanhash: | ceiling-stairway-carpet-salami |
| File name: | PROPERTY FOR SALE CYPRUS 300,000 EUROS.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 617'130 bytes |
| First seen: | 2020-12-26 19:00:26 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:x+qEl2UEH4HxA0c0oQ3TECcqhwrhmMHq3IpwCciXy/JTzJU:x+qEl2TH3g5itdpwyiI |
| TLSH | F2D4239176C8E1CF7CC21C278B5DDD91AAB80F093985BB3352580676D85DB8CAF4E4AC |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: server0.gbfasthost.co.uk
Sending IP: 193.39.253.100
From: Realtorlansbreysales <sales1@reinvest.com.cy>
Subject: Property Details In Cyprus, Check pictures and Prices
Attachment: PROPERTY FOR SALE CYPRUS 300,000 EUROS.gz (contains "PROPERTY FOR SALE CYPRUS 300,000 EUROS.scr")
Intelligence
File Origin
# of uploads :
1
# of downloads :
253
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-12-26 19:01:06 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.