MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66983eaf605ac1fa96b624d63c89c0922e830e133269f31baa727a98a07a7fa6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66983eaf605ac1fa96b624d63c89c0922e830e133269f31baa727a98a07a7fa6
SHA3-384 hash: 71edaba451b06dde5618d1cb3654a880cd1ef99db76a979b8d3ef8ff5b9eaef7ad93d8ed035ae93514e2895d05ad8581
SHA1 hash: ca7574537379172b204a691694c62e987a222d59
MD5 hash: 85f9aa0c7fa8813c3f83c502e30825f1
humanhash: jupiter-double-alaska-echo
File name:Proof Of Payment.rar
Download: download sample
Signature AgentTesla
File size:396'317 bytes
First seen:2020-05-08 07:09:15 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:o3rs0yMv2vAZR8exMmdv3ASgRKTJULSZGX:gs0zv2veR/WoASlJULh
TLSH B684237370016E65AA93DE8BFCFC59174437B5512EF012A95DB400BF2B26084B7B9A3E
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: rs108.zol.co.zw
Sending IP: 197.211.212.76
From: ngcume.siya<allan@melvin.gq>
Reply-To: <bonqanim@gmail.com>
Subject: Re: delivery details
Attachment: Proof Of Payment.rar (contains "Proof Of Payment.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-08 07:36:11 UTC
File Type:
Binary (Archive)
Extracted files:
65
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 66983eaf605ac1fa96b624d63c89c0922e830e133269f31baa727a98a07a7fa6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments