MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a82970a3c3308cd638c95012dab7a729eac38208e50f4ea3418774dd6df966a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 6a82970a3c3308cd638c95012dab7a729eac38208e50f4ea3418774dd6df966a |
|---|---|
| SHA3-384 hash: | c6a0868a626ed4a91aab2708c0b74d124dfca4393a7d3b57bd5c7f02a5a0e10d7b4e93e20abfe3b9f9f8adfca392524b |
| SHA1 hash: | efd42fd80f31d11bbd8bedac84c7562ee3dfec36 |
| MD5 hash: | a5b3ca7d8bfd5788a91d7749c7bf6236 |
| humanhash: | salami-william-vegan-twenty |
| File name: | purchase order.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 601'072 bytes |
| First seen: | 2020-08-19 14:47:03 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:dCJ/X2BgWWd3iSxWrm6PJUyTty6KReHp8t0fAtnQ1Bfyh/gJ:dg/2g/piSx+rp5KMHp8+fZ8h/gJ |
| TLSH | 92D423EC4AD560DCB1E0B98DB2C760C47FDD4118A8F23C4E05B6D242AB56D92BD0CB6E |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.makeitfunny.ro
Sending IP: 91.206.161.135
From: Matei <matei@makeitfunny.ro>
Reply-To: matei <obe.sales@hotmail.com>
Subject: Re : 새로운 주문
Attachment: purchase order.rar (contains "purchase order.exe")
AgentTesla SMTP exfil server:
mail.rgs-eg.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-19 14:18:08 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.