MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3fdb5f10d7f282d497fded321dd6f382977bde04d6638526b7d55cdbfb2ad824. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 3fdb5f10d7f282d497fded321dd6f382977bde04d6638526b7d55cdbfb2ad824
SHA3-384 hash: 74fa02f00a7f599906de694b76f7175f0b4fac938ce8a99e54df9cd0f3678389e913f6983d749d6be7f0ffa70817d142
SHA1 hash: 306b73744973b76d8b54fca69b2100c2e389d2c3
MD5 hash: 86c0c9555544727bb9fecde4e036094f
humanhash: table-avocado-cardinal-six
File name:ORDER FORMS.zip
Download: download sample
Signature AgentTesla
File size:662'039 bytes
First seen:2020-06-12 08:10:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:UkggcFh//38g9tg8kCTIv/DgVjQBErT5juCI16iZ:U4Mhnsm/s3UpQSn5juCUdZ
TLSH 77E42357D80F817BC203EC6F319AF2C1F8E74E8594AD3699EA8F268C757948CE465183
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: apollo.t.mk
Sending IP: 195.26.152.35
From: mareticdr@t.mk <mareticdr@t.mk>
Subject: BOOKING
Attachment: ORDER FORMS.zip (contains "ORDER FORMS..exe")

AgentTesla SMTP exfil server:
mail.radiomeff.mk:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3fdb5f10d7f282d497fded321dd6f382977bde04d6638526b7d55cdbfb2ad824

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments