MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e2b332abcf7beace6b200b85ddc85c5963b964b4f3d03d95796b4b8e5bbb8a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6e2b332abcf7beace6b200b85ddc85c5963b964b4f3d03d95796b4b8e5bbb8a0
SHA3-384 hash: fd1f355175231368020afad8dc29e011bb8610a4b28e8c9a0c2d7228df3d4b9537ece017a9718dd2d9f5c9bd86a84540
SHA1 hash: 09fe75f09395ab5a020659a5dd40844533f81ca0
MD5 hash: 4299f919d0ee64d0bbe33fedd6889292
humanhash: angel-crazy-table-minnesota
File name:Re Adjustment for advance payment.zip
Download: download sample
Signature AgentTesla
File size:391'196 bytes
First seen:2020-06-08 05:05:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:P0RU+evGZQnucF+chdlbrKscf+EZyApEOk+njA2lENjPoxO7WPcdfi0KJqeXxUm+:QU+eQqucQchdlvcyuw+jVGjwHzJtVS
TLSH CD8423F72BDBF7D4E595E50C67B9AB346125A42D24321036E65D081BFC6826F2FC2388
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: joister.net
Sending IP: 103.2.236.240
From: zreg@modern-ceramics.com
Reply-To: zreg@modern-ceramics.com
Subject: Re: Adjustment for advance payment.
Attachment: Re Adjustment for advance payment.zip (contains "Re Adjustment for advance payment.exe")

AgentTesla SMTP exfil server:
mail.haden-tours.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-08 05:06:07 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 6e2b332abcf7beace6b200b85ddc85c5963b964b4f3d03d95796b4b8e5bbb8a0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments