MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a54d6b38525684c571bb59b0b3311683378f0c689e6180a1aa9c72b1c83fe8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5a54d6b38525684c571bb59b0b3311683378f0c689e6180a1aa9c72b1c83fe8e
SHA3-384 hash: bc6abcc59179f66457a7671617b5fb01d108f2f6e41825c0c484e79c35c0ef67cb01773eb347e39df589ea27b229db30
SHA1 hash: 3f85006c6836aa03776180ef1b3808a6ab53b9a3
MD5 hash: 98a5df64908e8b909f441726ecc6c960
humanhash: violet-cat-ack-pizza
File name:PDF FILE.zip
Download: download sample
Signature AgentTesla
File size:508'768 bytes
First seen:2020-08-13 08:55:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:mNyzCxWa2VnkiHG7CKbakFwL4iEU2SUzgETTpAVer/l:xzCoawkiHoawpU26E5AVerN
TLSH 55B423EFDF17588BC078A4F463F2A4561E25E215138BDA3F44BB5CB287360452B9AC32
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ansmtp.ariba.com
Sending IP: 185.222.57.136
From: SMr.Masum Rana <s4system-prod+jsw.Doc2557668176@ansmtp.ariba.com>
Subject: Payment Confirmation Advice
Attachment: PDF FILE.zip (contains "PDF FILE.exe")

AgentTesla SMTP exfil server:
mail.wingsofmusic.com.au:587

AgentTesla SMTP exfil email address:
seed@wingsofmusic.com.au

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-08-13 08:57:03 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5a54d6b38525684c571bb59b0b3311683378f0c689e6180a1aa9c72b1c83fe8e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments