MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4740269d57edafa8b16f28e9e373290f2a8acc068dbc0e5d5f05f75d34e0613e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4740269d57edafa8b16f28e9e373290f2a8acc068dbc0e5d5f05f75d34e0613e
SHA3-384 hash: a1480b6090cc72df25582f5aa0bcff8a38ef7946e60ebb5222a7d034204191b518dbd3058448b2577dafb918cee595a6
SHA1 hash: 708ffc9be7492aac929f09e8e51ae3d6b42476d8
MD5 hash: 09e90cd542eed727cdea7c0c836cdcde
humanhash: alabama-oven-arizona-lithium
File name:Statement of Account.gz
Download: download sample
Signature AgentTesla
File size:277'606 bytes
First seen:2020-06-11 06:13:41 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:Py1x+eNqAt29KLhSdXzoIp1mIQFVhj5JjeSrgjFf1gJobTUMso:Py1lNT49KWzoi1IFVhjDTgh1gJu1
TLSH F74423CF57EAB30031575A1F7CCE586E516ED3C0EBA326B50069E0EA00E9D56234B5EE
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hitecprinting.com
Sending IP: 209.58.149.66
From: Hitec Printing Press <info@hitecprinting.com>
Subject: SOA
Attachment: Statement of Account.gz (contains "Statement of Account.exe")

AgentTesla SMTP exfil server:
smtp.badamli.az:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-11 06:15:13 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 4740269d57edafa8b16f28e9e373290f2a8acc068dbc0e5d5f05f75d34e0613e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments