MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ba2d6a62db8d5d67182c3420b24f6825723ac3f550f3288e77d395433cb5076. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6ba2d6a62db8d5d67182c3420b24f6825723ac3f550f3288e77d395433cb5076
SHA3-384 hash: 17058a28f76ae99d4de6bd69bf65c464a9274e6b167552393b79baabf55b4481dc7d47dd7cee31a4ec3dcbbaee4442d2
SHA1 hash: a8e32527cdc391ea66743a77c9f887bcd9079f18
MD5 hash: 50926030fbc2e6388290bb05b84a5cc4
humanhash: dakota-cold-april-cold
File name:new order.gz
Download: download sample
Signature AgentTesla
File size:482'742 bytes
First seen:2020-08-16 13:58:55 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:rLJo2/mvNHY0SIT0tCPMhLjqyX++zfjWOdZAOTP:3CqYNBSkZQLjlfnF
TLSH ECA42372793809DDD4641E0AC29EBD92133FE4FED735CBA64DCEA34898A65B110972CC
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: intermetal.com
Sending IP: 185.222.57.157
From: Elmer Lipardo <elmer.lipardo@intermetal.com>
Subject: RE: Re: Inquiry// Meeting Table// Final Payment
Attachment: new order.gz (contains "new order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-08-16 14:00:08 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 6ba2d6a62db8d5d67182c3420b24f6825723ac3f550f3288e77d395433cb5076

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments