MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5dbad096973f57d3ce0d39a35461c1e5dcc304f7b5e249db2a3991d8f9289aaa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5dbad096973f57d3ce0d39a35461c1e5dcc304f7b5e249db2a3991d8f9289aaa
SHA3-384 hash: 3121579137fddae2b81158002c57172da7ea466f056fe4d1d82da4c461859e501b8d34121af51b763de9b546bd4e0bbe
SHA1 hash: f5b5343cb24cd3c162f4afcc5f865a265148e9cd
MD5 hash: 3d58165f5306da89e79bb841b40df0ae
humanhash: mississippi-fix-cold-robin
File name:Invoice Doc.PDF.cab
Download: download sample
Signature AgentTesla
File size:347'418 bytes
First seen:2020-10-13 07:40:56 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:b6hoEk/CZ1BlqrS20SIy1qKTzJe69TvAA3wrp8PFdYembCdeU+lRTzzqSo6:koElZDlqrS20Svkce6Aawrp8PvYfbCdC
TLSH 5A74237436FBDB62B1EFBAE80D7049E457632B09404D0DCB7BF86853FA6E04A249845D
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cvp0.111.vuere.ml
Sending IP: 165.22.115.71
From: Accounts Department <info@swmianllc.cf>
Subject: Payment Advice
Attachment: Invoice Doc.PDF.cab (contains "Invoice Doc.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-13 02:06:33 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 5dbad096973f57d3ce0d39a35461c1e5dcc304f7b5e249db2a3991d8f9289aaa

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments