MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 53c7200306d0e1c4198b5b8357dfdb855481d0f758dc2f6bd5188d04c2b03afb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 53c7200306d0e1c4198b5b8357dfdb855481d0f758dc2f6bd5188d04c2b03afb |
|---|---|
| SHA3-384 hash: | 6796e2b76e30afa97b1e421bdc92baedd131897e42b4d5c1255fab4ac7cd6cb655d3d19ff81596422e6c7ca45b10caf7 |
| SHA1 hash: | 692f4d4b2598eb5703d7dbd3c6f03e78e7714134 |
| MD5 hash: | 91b5624eec7e9b4b4b8dcc56b0613fab |
| humanhash: | fillet-nineteen-delta-winter |
| File name: | China Business Proposal English.pdf.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 42'373 bytes |
| First seen: | 2020-10-19 06:34:34 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 768:sawHYXniTWmS4NjCP/TZgjgef3UNdqVknlC+ns9in6Hh:svHbCmSCjsbnwVk4+s9cS |
| TLSH | 1B13F1D178A15FF2EFF506B9E4B5CA432EF097CCF802651A7A324844DE9352638C96D2 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: aland.net
Sending IP: 209.58.149.123
From: Procurement<jianxaou@aland.net>
Subject: China Business Proposal(ENGLISH VERSION ATTACHED)
Attachment: China Business Proposal English.pdf.zip (contains "ebuka.exe")
AgentTesla SMTP exfil server:
mail.soaluga.pt:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Stelega
Status:
Malicious
First seen:
2020-10-18 21:13:34 UTC
AV detection:
19 of 28 (67.86%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Dropper
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.