MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5ce8c4d2e12543d6c237e1f98c76c6daff01b3e477c40e5abeea39afb7327da0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 5ce8c4d2e12543d6c237e1f98c76c6daff01b3e477c40e5abeea39afb7327da0 |
|---|---|
| SHA3-384 hash: | 77dd3c6d80cde9b13abf6a5d6079aec2e0ae7221cc1d465b150b57bcc555e8213ec4e52a9dfb163c79694fe33d6c0adb |
| SHA1 hash: | 741102a6813d1561292a8169e1f0dad030db2fc0 |
| MD5 hash: | 080e4d79d6178bdc12ab39a8fac1a75f |
| humanhash: | whiskey-asparagus-foxtrot-nevada |
| File name: | Transfer Forms.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'703'936 bytes |
| First seen: | 2020-07-30 07:05:58 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 24576:RHUmUUEkNR9wX4tpJ2S7rZd1u5qVlHNjwTslX7XA:1Um6XEJ7UqVltfl8 |
| TLSH | 4675D0057A50E56EC67F8F72D6894800DFF4B8AE8607E38F74C573AF29CB36A9406161 |
| Reporter | |
| Tags: | AgentTesla Endurance img |
abuse_ch
Malspam distributing AgentTesla:HELO: 162-144-100-85.unifiedlayer.com
Sending IP: 162.144.38.36
From: PAY-U <enquiry@oxy99.in>
Reply-To: PAY-U <account@payu.com>
Subject: INCORRECT BANK DETAILS FOR PAYMENT
Attachment: Transfer Forms.img (contains "Transfer Forms.scr")
AgentTesla SMTP exfil server:
mail.northwestpowdercoating.co.uk:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-07-30 07:07:13 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Farheyt
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.