MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 332c7480767596c1cdfa6f06b6f6f501e5a1b25e86569334f3b8bf0a67c725e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 332c7480767596c1cdfa6f06b6f6f501e5a1b25e86569334f3b8bf0a67c725e5
SHA3-384 hash: 67579fe8178e9b8f70994e908e64b383f02170797906af12f7ed0b01e01b57bdc2f5b081d6d5bbb8cb6b9e7fc8431981
SHA1 hash: 951dbaab068d235450b49ca0910e9e0408ba3d22
MD5 hash: 6ff9c32631df868b3d498e43efd35116
humanhash: salami-vegan-three-north
File name:PT SANDAND==PO.C-SMD.2001-019.gz
Download: download sample
Signature AgentTesla
File size:268'702 bytes
First seen:2020-06-15 13:54:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:NkfQjyBhC+yOt89SyTfc2UYZ/Cskye5kj6fwC0Td:NkojGy488yXUYp/DckKcd
TLSH BB4423349C4443EAABA518BE11E00EA1E77B4C47940A57C9DBF78AE3D1E9191B1AF313
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ns1.lebisoft.com
Sending IP: 217.116.200.64
From: PT SANDANG ASIA MAJU ABADI <Sales@sandangasia.com>
Subject: RE: Order Confirmation (PT SANDAND==PO.C-SMD.2001-019)
Attachment: PT SANDAND==PO.C-SMD.2001-019.gz (contains "P.O 5790334791342.exe")

AgentTesla SMTP exfil server:
mail.chenklins.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Injector
Status:
Malicious
First seen:
2020-06-15 13:56:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 332c7480767596c1cdfa6f06b6f6f501e5a1b25e86569334f3b8bf0a67c725e5

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments