MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 895ebd9aeff0a60c2c7c71ff35ee155c337e8597a43d9014e272987be47bf867. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 895ebd9aeff0a60c2c7c71ff35ee155c337e8597a43d9014e272987be47bf867
SHA3-384 hash: e2c244d30c5d563bd44e5c799f1a365c3f49e0d3eb995634d5e82a9166116edc2545de6c2e42abf5169b82a3f04cddbc
SHA1 hash: a36752063f026c41266ea567904a6525fd464193
MD5 hash: a5ee1729c9ba3aa7c9a0ac013b119a72
humanhash: finch-four-fanta-kitten
File name:Factura.rar
Download: download sample
Signature AgentTesla
File size:524'947 bytes
First seen:2021-01-06 07:16:47 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:43M6menhrbqJ83VXKPVbmhxA4ZVjM/Q+9bJaq7AS6SSv8g:4XmuquVXomNfDGbp7AtN
TLSH 2FB4237070FEDD440BEE51D97F3A7BC084D9878BA88AD9E9DDA32E0740339A8570C465
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 171710.MONOVM.COM
Sending IP: 23.227.203.24
From: Katherine@171710.MONOVM.COM, Alvarez@171710.MONOVM.COM, Guarniz@171710.MONOVM.COM, info@bcainvestors.ml
Subject: FACTURA
Attachment: Factura.rar (contains "U6ODBh62dJ0IYCK.exe")

AgentTesla SMTP exfil server:
mail.chefoowork.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-06 05:37:43 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 895ebd9aeff0a60c2c7c71ff35ee155c337e8597a43d9014e272987be47bf867

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments