MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85a06f65f6735866e60a9396f7ca92b82aa08528d3fea8ed1f25d4623fe8a9ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 85a06f65f6735866e60a9396f7ca92b82aa08528d3fea8ed1f25d4623fe8a9ec
SHA3-384 hash: a24b3fcb3fa7cecb52d350a18be7efb1a85370b946214b6f39e61f88039e06df9bcf0a596000fcbfc12f74117faa2df3
SHA1 hash: a9424d3d0f8a3a66c5ba97be0f5031b6bb01977b
MD5 hash: 2ac3ed22421ce6f307947334d7a49680
humanhash: mountain-zebra-freddie-california
File name:ReleaseOrder_JLN14TJ2006302B_202019.zip
Download: download sample
Signature AgentTesla
File size:405'290 bytes
First seen:2020-06-19 06:52:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:A52j6xIKCQ3vQNMGwzuWbf8ad+Gqr+pAHBq:AXIRQ/Qu7bld+Gqr+Es
TLSH 56842384E608C950DEA7FD06F37FA93CC5157B1748B47A0A7A2E234150766DECA221FD
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server30.fnp-web.com
Sending IP: 180.147.250.17
From: Cici Chu / CTL TJN <deckow@rebingul.us>
Subject: JLN14TJ2006302B 展濠 Re: TO HONGKONG Arrival Notice
Attachment: ReleaseOrder_JLN14TJ2006302B_202019.zip (contains "ReleaseOrder_JLN14TJ2006302B_202019.exe")

AgentTesla SMTP exfil server:
mail.sevenstars-travel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-19 06:54:07 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 85a06f65f6735866e60a9396f7ca92b82aa08528d3fea8ed1f25d4623fe8a9ec

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments