MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 630f08ff9ba1d031c0fb428da546c7e0991295165d6a56afa86f3832aace5f24. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 630f08ff9ba1d031c0fb428da546c7e0991295165d6a56afa86f3832aace5f24
SHA3-384 hash: 2579e797b40e63ffc1f75725e9a446bb56e5514d480373d933e42b2833d949fd42763f02c4a19c2a861a424a3320d2e2
SHA1 hash: 923403507d13e14e7f78260711729739171985b0
MD5 hash: 09489fcafbd8837e0949333f04b206c6
humanhash: equal-december-single-spring
File name:13 W04-BOD01 MOLD.X.uue
Download: download sample
Signature AgentTesla
File size:219'556 bytes
First seen:2020-08-12 06:47:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:UOlcuE1JzAnjJHbgf9fJFytXeKxrBQ45LFyk77mr7L:MXmjVqyVeKx9Q45pyk7iHL
TLSH A024236AF34677B1E4FF6C956E05794C90AA32842039C8BD95AD304DE05B2BF7B00E57
Reporter abuse_ch
Tags:AgentTesla MailChannels uue


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: bumble.larch.relay.mailchannels.net
Sending IP: 23.83.213.25
From: Ivaylo Iliev <sales@bkoikn.xyz>
Subject: RE: CNC mold quote (BOD01 Mold)
Attachment: 13 W04-BOD01 MOLD.X.uue (contains "13 W04-BOD01 MOLD.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-12 06:49:04 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 630f08ff9ba1d031c0fb428da546c7e0991295165d6a56afa86f3832aace5f24

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments