MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26f2cc9f58730871051f0722600a93b2d3f8ac3f306ec53ca0b340f3baf58884. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 26f2cc9f58730871051f0722600a93b2d3f8ac3f306ec53ca0b340f3baf58884
SHA3-384 hash: 7c6563a9ae512b405053cfbedd9d7a709a8bbe62ea92a05353bb9d61ae1d934cbfb59e3480dbe08af41b3b1973e1ccb6
SHA1 hash: ae3747fd5916d882cac924b1f8c069e818feb5e8
MD5 hash: fdc16c6bb65ef687116e920086dc1edd
humanhash: stream-lactose-carbon-twenty
File name:new-order-001.xz
Download: download sample
Signature AgentTesla
File size:1'276'764 bytes
First seen:2020-05-05 10:58:42 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 24576:+EPTW641pohfEYoY+Xuwyeikrkejxn0N8b9L7vQNDrMQ2FGL3:+EPTWh1ON1A7H9Ysv0MvI3
TLSH 724533ADCFF514AECE35C203E5543415E5A85017B84BDDF3C439DA6F9AAC2AE098470B
Reporter abuse_ch
Tags:AgentTesla xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: simafri21.uk.plesk-server.com
Sending IP: 87.239.21.32
From: Muhammad Saleem <vahidbar.arvand@gmail.com>
Reply-To: vifeki3@yandex.com
Subject: NEW ORDER SPECIFICATION; GREECE:
Attachment: new-order-001.xz (contains "new-order-001.exe")

AgentTesla SMTP exfil server:
mail.elsewedyindustrial.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-05-06 03:36:03 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

xz 26f2cc9f58730871051f0722600a93b2d3f8ac3f306ec53ca0b340f3baf58884

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments