MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6367344913dbd4972a8a3a0e8ff0d323b1bb917ff01477a7c9364b7c3336a538. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6367344913dbd4972a8a3a0e8ff0d323b1bb917ff01477a7c9364b7c3336a538
SHA3-384 hash: b135e623986967b60d299415b7befe3c8bb70d24298926d1e13569ded6bb75603f38b40fa714e31473578b657a9af38b
SHA1 hash: c7127858317fec87af867bf17462cb8eebce4aa0
MD5 hash: 65fa2d4854f5ec15f8702e9c390b2279
humanhash: west-bulldog-spaghetti-friend
File name:TT copy.zip
Download: download sample
Signature AgentTesla
File size:677'866 bytes
First seen:2020-10-06 17:54:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:8nS3Jyt3qkcSkipfI9O0SC8nuxGbjkcX/4f02AsCSn582LGrPUqx4qRRt+5qs:8nS3JAcAIMnjj2fBAZGbLGrPxx4GQqs
TLSH 7FE423B18ACAB8B8808952DEF11F331B1C15AE5C5078F3D9F8E1675E5B0DB7740279A8
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: webmail.cyber.net.pk
Sending IP: 203.101.175.37
From: Lisa <airmaster@cyber.net.pk>
Reply-To: procuregtscorps@aol.com
Subject: Payment transfer
Attachment: TT copy.zip (contains "TT copy.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 6367344913dbd4972a8a3a0e8ff0d323b1bb917ff01477a7c9364b7c3336a538

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments