MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e3459c2dde283b7de501a2a1cd3e1d3df2f90a95aead4b021355b605f32fc5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6e3459c2dde283b7de501a2a1cd3e1d3df2f90a95aead4b021355b605f32fc5d
SHA3-384 hash: 6ebfc68f473896e8db7ae2e4a8a24abbbd4ddce127e1c1e55e45ac1772ead852429dd8ce6f229057978d55ece909c031
SHA1 hash: 32da49602cf3ab5358c7ddb260b98fe7a75cfecd
MD5 hash: 3ec5c14a317042d99fc2ffbdf7f1f887
humanhash: skylark-fifteen-butter-twenty
File name:Other Counter CORONA Virus Medical Protection Materials_.7z
Download: download sample
Signature AgentTesla
File size:1'092'512 bytes
First seen:2020-04-02 15:38:16 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 24576:MSVQ6fccjo3P+vp8TDfRMI2FenNSXxyI8W8KRUTmyRtFB0OIHRDEqFV:Mlrmvp8TjWI2cNUktNKC6GtFB8lFFV
TLSH 4435331F81177401232A648CC278EC42D6D4AA38523DA88B2F78FE9FF599C58BCD7765
Reporter abuse_ch
Tags:7z AgentTesla COVID-19


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: yahoo.com
Sending IP: 62.113.215.228
From: solar.seekerxu88@yahoo.com
Subject: Fw: ,Hand Sanitizer,Gloves, Coverall, Temperature Gun for Anti-COVID-19...
Attachment: Other Counter CORONA Virus Medical Protection Materials_.7z (contains "Other Counter CORONA Virus Medical Protection Materials .com")

AgentTesla SMTP exfil server:
mail.leltbank.com:587 (198.54.115.208)

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-02 16:35:27 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
18 of 47 (38.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 6e3459c2dde283b7de501a2a1cd3e1d3df2f90a95aead4b021355b605f32fc5d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments