MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57a138e7d0645a32ff98c47f4cc6ea8464cfee590ebef4a1560caeeceb0a0d99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 57a138e7d0645a32ff98c47f4cc6ea8464cfee590ebef4a1560caeeceb0a0d99
SHA3-384 hash: 28ad035185eab6fa1c25eba6e7939b830d198857dc12599ec59d7a38f8ceba3e93ca1c084d240da4ad86373a80820b1d
SHA1 hash: 83df6b56df4e8d225472afedfd0d4b3b29b868fe
MD5 hash: e7268b5367c4076e08efc0bc47e55b1a
humanhash: william-east-wolfram-july
File name:Payment.zip
Download: download sample
Signature AgentTesla
File size:400'720 bytes
First seen:2020-08-12 15:52:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:buW5a55sQKvRLLHe/a5KB2Z5RB76GgKAf4F/K3e:Ra55sVJP95tXTj7F/K3e
TLSH 60842320BEA18205F644EF4497DCB39A73D51E65FA3B3841F7D8F484AAA634E5335CA0
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic312-19.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.244.209
From: Golden Trade Ltd <goldenjlbd@yahoo.com>
Reply-To: goldenjlbd@yahoo.com
Subject: Payment Update
Attachment: Payment.zip (contains "Payment.exe")

AgentTesla SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-12 15:54:09 UTC
AV detection:
5 of 47 (10.64%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 57a138e7d0645a32ff98c47f4cc6ea8464cfee590ebef4a1560caeeceb0a0d99

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments