MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ad70dc95ae7e7d446a069e1d76157370c462c1fe84892c7ca08c13da517bebc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7ad70dc95ae7e7d446a069e1d76157370c462c1fe84892c7ca08c13da517bebc
SHA3-384 hash: bb98d7ca66afe31a6ad21ddc78aed315a329899114ea3d0a924d1bcbd0cf6827916f2ea65b9975240f8636aff22ea44c
SHA1 hash: 226f49cbe0c6d3828b425ab010fea23282aa1d0d
MD5 hash: 83b1d28fd15723f3ab1299bbfe148eb6
humanhash: uniform-red-mirror-missouri
File name:PO-11059021022021.zip
Download: download sample
Signature AgentTesla
File size:374'949 bytes
First seen:2020-06-19 16:46:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:0suKvXSFOR4RIbhvUU8LIjagDxodkhytybjMQX46J/SAsVOlEVIlx2V7if+SK+me:0sZiFOR4+qUwIm20EXVo601VOlEif3vL
TLSH B9842358473EC2D1E13266BC6977F29DCAF6C3A1C09EC36C7EA050A3CE524AB9135532
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: iap-india.com
Sending IP: 38.130.220.104
From: karthika.p@iap-india.com
Subject: Purchase Order (Ref: PO-11059021022021) - Project: Redhill L14 
Attachment: PO-11059021022021.zip (contains "PO-11059021022021.exe")

AgentTesla SMTP exfil server:
mail.standard-engg.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-19 17:35:48 UTC
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 7ad70dc95ae7e7d446a069e1d76157370c462c1fe84892c7ca08c13da517bebc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments