MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 861c707a21bca7d11c505f82c7bd0d1be7f9f8ca547a822755d418942bf1a89f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 861c707a21bca7d11c505f82c7bd0d1be7f9f8ca547a822755d418942bf1a89f
SHA3-384 hash: 823339f48dd39635c3189cc241f83255de65f87b162f93fa24a1f4edb68aa05bef9f7a1ad0e3bd6889da9ea67441b15d
SHA1 hash: 1fd4b09fe85245cd90240ffeaa8a8c624b22c9e4
MD5 hash: 7a527769f6894b0999c361ad93a336e9
humanhash: lithium-yellow-oregon-timing
File name:Scan Invoice_pdf.gz
Download: download sample
Signature AgentTesla
File size:471'815 bytes
First seen:2020-06-02 06:49:42 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:cIG8aHJyGBsdNsuamsBx+8YUEWTW8mOxMMNBR9:28Jrnu+86IW8mOBr
TLSH 78A4236492A7D8C3BC84D4D687BC6726D42E749BBD04568E3C00FEE6492E6121DC2EFD
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: staging.maykenbel.com
Sending IP: 195.12.49.182
From: Rafał Gąsior <rafal.gasior@astoria.pl>
Reply-To: Rafał Gąsior <rafal.gasior@astoria-pl.com>
Subject: RE: URGENT-Confirm Account Details/SOA Feb-May
Attachment: Scan Invoice_pdf.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 00:53:55 UTC
File Type:
Binary (Archive)
Extracted files:
286
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 861c707a21bca7d11c505f82c7bd0d1be7f9f8ca547a822755d418942bf1a89f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments