MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c0fff27b47ebe46df4e06ffddd0eea73210599a41a04c02680c819f9a301c3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2c0fff27b47ebe46df4e06ffddd0eea73210599a41a04c02680c819f9a301c3d
SHA3-384 hash: 4d50580f5da4595db15ad33248df50907f12c2452448aa562ad6db0fc4611e8e3f7e0cecc5ef336413e7bf89be08312f
SHA1 hash: 7f5e595e8ba6e3d4d397982a5645a346cef93649
MD5 hash: d50b03270d49e1ba2fb2e3e6ca95b739
humanhash: sixteen-connecticut-foxtrot-washington
File name:SI,, packing list_images.rar
Download: download sample
Signature AgentTesla
File size:158'902 bytes
First seen:2020-07-02 12:32:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:/HY8KLU1fW7Z9SflDJ9R8hF5ardOWBZna6B9BihSt9vrJ7Nyc2qEroeTICspDRR:gjU1fW7fSr8taUiD0u9rJ7L2fgV
TLSH 39F31236DF37F4647464A2B2D272E982FC1570D7CAC76BABF8A45D3E87CB2A90601005
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.example.com
Sending IP: 103.147.184.169
From: KOREA COUPLING CO., LTD <sales@koreacoupling.co.kr>
Subject: FWD:Important Notification:SHIPPING DOC BL,SI,INV#462345 // MAERSK
Attachment: SI,, packing list_images.rar (contains "INVOICE_IMAGES.exe")

AgentTesla SMTP exfil server:
smtp.office365.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-02 12:34:05 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 2c0fff27b47ebe46df4e06ffddd0eea73210599a41a04c02680c819f9a301c3d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments