MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6941451d98804a87065751a21a8785d2c46d468ecbae2e7e03000d374cbdc9ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6941451d98804a87065751a21a8785d2c46d468ecbae2e7e03000d374cbdc9ae
SHA3-384 hash: 9ae58e6385c8a591114215d5fa60de6a89adecf98960a7b9e2377415107b666209b652f1b2e9fb2814643c6774065b39
SHA1 hash: 863a647a700278459e8c2220b7b61ba3ae43a89d
MD5 hash: 8e882b9dbeba73a6db47650fe46b6758
humanhash: orange-item-glucose-pip
File name:signed_19272.rar
Download: download sample
Signature AgentTesla
File size:992'314 bytes
First seen:2020-06-02 10:46:11 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:auKqTjC4Cl4VgMMDtamA4HDnXBdnu/rIn/xGz:auKkF89r7/u/rUGz
TLSH 83252387EF97D7092DBF87E316C0451B9EF04439BA87699896259F0B850FF189B0C274
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chasisautopartsengine.com
Sending IP: 103.99.1.147
From: arnis janvars<arnisjanvars@chasisautopartsengine.com>
Subject: RE: Signed_document for urgent_shipment 
Attachment: signed_19272.rar (contains "signed_19272.exe")

AgentTesla SMTP exfil server:
mail.parshavayealborz.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 20:09:00 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 6941451d98804a87065751a21a8785d2c46d468ecbae2e7e03000d374cbdc9ae

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments