MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 338bb883a90cf9d0b6ecef694c0e752e6c92c943f3de596618a0e5e8df02586e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 338bb883a90cf9d0b6ecef694c0e752e6c92c943f3de596618a0e5e8df02586e
SHA3-384 hash: 9d69a20c58197e7f9198dbcbf4f94e312f71f92fc2ad6dcfcab0549991b97364d848dbb219cc6269224b36b41926b625
SHA1 hash: 302e28d8c4be32aaa410a245352319a65c26a864
MD5 hash: 88f1f56b400612cfadda33950cf1b77b
humanhash: avocado-sierra-iowa-hot
File name:Payment Copy001pdf.rar
Download: download sample
Signature AgentTesla
File size:959'482 bytes
First seen:2020-07-07 12:52:53 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:RyW8OwQBX7zQ2DkE48DMMTctfTtfhuJXkqJ6XDiYf:WstkEHhTc4XkXzie
TLSH 6015338F0066EF9672FD521EB4104ACDC268DD4AAE9F9E3614073CDD48CE65121DDCEA
Reporter abuse_ch
Tags:AgentTesla rar Yahoo


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic310-19.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.244.139
From: prakash mehta <peeteeextrusion@yahoo.co.in>
Reply-To: prakash mehta <peeteeextrusion@yahoo.co.in>
Subject: Scan Payment Copy
Attachment: Payment Copy001pdf.rar (contains "Payment Copy001#pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-07-07 12:54:10 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 338bb883a90cf9d0b6ecef694c0e752e6c92c943f3de596618a0e5e8df02586e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments