MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3efde2b997fc11c099859b072135a68b74f79857c9e7a31d339c69f1e3a7f05f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3efde2b997fc11c099859b072135a68b74f79857c9e7a31d339c69f1e3a7f05f
SHA3-384 hash: 46b2888a015a16da69cd6603f2287fd64930c1e5b09058982d7f6dcb9bf1b46d804ad41a128b52e762092fda94b5643f
SHA1 hash: 3611b93a83e7bebfadbb11f81061b07f1f53dc00
MD5 hash: 2e596665b1005089207e3ba4ff9b239c
humanhash: carpet-river-tennis-tennis
File name:BANK ORDER COPY 2.rar
Download: download sample
Signature AgentTesla
File size:1'004'975 bytes
First seen:2020-04-29 18:23:16 UTC
Last seen:2020-04-30 03:51:56 UTC
File type: rar
MIME type:application/x-rar
ssdeep 24576:5UxV/EZys+FJ6n2Q7cUB/+pQHzgr5kCBTvh0paUhyo1RM:5UHFhKPTg9nV0plwUG
TLSH 5B25335900D0A2DEFAE053D61BC1535165E2ACD37440BAB14EA34B68D9EFC84F3ACEC6
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.medopharm.in
Sending IP: 43.254.108.196
From: Sakthivel C <gmplmaint@medopharm.in>
Subject: OUTSTANDING PAYMENT//Original Scan BANK ADVICE.#47650
Attachment: BANK ORDER COPY 2.rar (contains "BANK ORDER COPY (2).exe")

AgentTesla SMTP exfil server:
mail.dadupipes.com:587 (162.215.253.215)

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 18:36:00 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3efde2b997fc11c099859b072135a68b74f79857c9e7a31d339c69f1e3a7f05f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments