MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6
SHA3-384 hash: a4a4a798a5b93bd7a1dce7003b3043eab96ef63cd07b87aa4b44b687f304b9bf21e4eb3b35f2515c8f03e4f918431ea8
SHA1 hash: 2b95007e06e3a8df3e37e13d8e5b04ba49ca3c80
MD5 hash: a0b5f5ae3e5c584d5d05d3024a6c2719
humanhash: zebra-summer-sad-ack
File name:SOA JUNE.r00
Download: download sample
Signature AgentTesla
File size:241'355 bytes
First seen:2020-06-30 12:26:17 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:4HVoB3tadkwmahcvqwNHDYjb8Zz+JBUtuwcFeQ:4HC3pvpGsV+kQ
TLSH 6034231D04C26B8FB21BC33848E651B65C7B37A663D5D4BC8E057E9494E36C1E6B322A
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ibd.net.bd
Sending IP: 103.207.38.153
From: Finance<faisal@ibd.net.bd>
Reply-To: thomasbaby.gulfhousemedical@hotmail.com
Subject: SOA of June 2020
Attachment: SOA JUNE.r00 (contains "SOA JUNE.exe")

AgentTesla SMTP exfil server:
mail.chinagrill.co:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-30 12:28:05 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments