MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e4bfdc8ad33b9db51942e590893890d58a2f385c2427f3fc5cafc455377be99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3e4bfdc8ad33b9db51942e590893890d58a2f385c2427f3fc5cafc455377be99
SHA3-384 hash: f4a53b3ae63463111bcba2fb1d741e864d1061409c9b8cee8d8f8b836f28526a3e8e6b12803c718bd9ab70b9359070e2
SHA1 hash: de6c9f8028c64c1ebd0673fa7702c10a39e54672
MD5 hash: 2c73df30b35f37c18d06f260b32da33d
humanhash: romeo-pasta-four-quebec
File name:W001_G020_PO201207320.zip
Download: download sample
Signature AgentTesla
File size:507'852 bytes
First seen:2020-12-28 07:59:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:gGTwJgJMfG0wQWEdpsntYcnJpAmokjxQH28KAce8d05WV4Su:r3u+6VMnoTm+4e8ys+t
TLSH 02B423285DE7067E7B8836BEB182194B5B305C15B4842CDBF18D32E9F7A92B760CE059
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cloud.tihest.org
Sending IP: 50.31.134.128
From: maggie xu <maggie.xu.aibo_group@vip.163.com>
Subject: (G020)新订单PO201207320
Attachment: W001_G020_PO201207320.zip (contains "W001_G020_PO201207320.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
447
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Backdoor.Remcos
Status:
Suspicious
First seen:
2020-12-28 08:00:07 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3e4bfdc8ad33b9db51942e590893890d58a2f385c2427f3fc5cafc455377be99

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments