MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7877282e1ab66e4bcffe816b79de4db8fbe13b3819bb07f917d8b6835b51f6e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7877282e1ab66e4bcffe816b79de4db8fbe13b3819bb07f917d8b6835b51f6e6
SHA3-384 hash: 442db951236dec99b59f8f034499965c1c0be875f183a7b605ef40be8053213fc46c20bd09131713f653a49e56db23fb
SHA1 hash: c1527b6c1ef53a95e5540ec3b157ba67487f204f
MD5 hash: 132ea8d1e6bc830c88836f3e99f4be5b
humanhash: magnesium-michigan-finch-timing
File name:InvoiceIA20100255.gz
Download: download sample
Signature AgentTesla
File size:479'341 bytes
First seen:2020-10-27 09:16:25 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:a1SWrZMr5fLtnzLguB5XaBcZ3OAt21Ijo1GHZ:aQqMFD5EuTKu3OIjf5
TLSH E2A4239A07DF8CF1B62EC579F80E37F919B725902D0762A8D81C06A7661801B3D1F6ED
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: filter.bbts.net
Sending IP: 119.18.145.4
From: Aquatrans.Ops <aquat_ops@bbts.net>
Subject: PO#2065_Invoice#IA20100255
Attachment: InvoiceIA20100255.gz (contains "Invoice#IA20100255.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 7877282e1ab66e4bcffe816b79de4db8fbe13b3819bb07f917d8b6835b51f6e6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments