MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a82970a3c3308cd638c95012dab7a729eac38208e50f4ea3418774dd6df966a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6a82970a3c3308cd638c95012dab7a729eac38208e50f4ea3418774dd6df966a
SHA3-384 hash: c6a0868a626ed4a91aab2708c0b74d124dfca4393a7d3b57bd5c7f02a5a0e10d7b4e93e20abfe3b9f9f8adfca392524b
SHA1 hash: efd42fd80f31d11bbd8bedac84c7562ee3dfec36
MD5 hash: a5b3ca7d8bfd5788a91d7749c7bf6236
humanhash: salami-william-vegan-twenty
File name:purchase order.rar
Download: download sample
Signature AgentTesla
File size:601'072 bytes
First seen:2020-08-19 14:47:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:dCJ/X2BgWWd3iSxWrm6PJUyTty6KReHp8t0fAtnQ1Bfyh/gJ:dg/2g/piSx+rp5KMHp8+fZ8h/gJ
TLSH 92D423EC4AD560DCB1E0B98DB2C760C47FDD4118A8F23C4E05B6D242AB56D92BD0CB6E
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.makeitfunny.ro
Sending IP: 91.206.161.135
From: Matei <matei@makeitfunny.ro>
Reply-To: matei <obe.sales@hotmail.com>
Subject: Re : 새로운 주문
Attachment: purchase order.rar (contains "purchase order.exe")

AgentTesla SMTP exfil server:
mail.rgs-eg.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-19 14:18:08 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 6a82970a3c3308cd638c95012dab7a729eac38208e50f4ea3418774dd6df966a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments