MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8afe3c84880cd4faed0068712abe638b934f7e4799cd4beaf6dea4151e511272. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8afe3c84880cd4faed0068712abe638b934f7e4799cd4beaf6dea4151e511272
SHA3-384 hash: 72e1eb52a78c654ccf694b1c3e6ebb4db9fbc0c924504143160d9aab1b2a908abf819ebde5b89421219b4a6557d361d4
SHA1 hash: b1094632f8cb03dc3541ec45610e8a7325c23286
MD5 hash: a79fccc94ef8e1357e81ddc30a694a36
humanhash: iowa-mexico-bacon-queen
File name:purchase Inquiry -pdf.zip
Download: download sample
Signature AgentTesla
File size:1'051'038 bytes
First seen:2020-06-10 11:44:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:8ptoS6TNY73idvNvKJFegrPEvR/ds2WEjP4yg8bJ5JEQ0IA:83kNNNyJQgrP2TDgwJ/jA
TLSH 1925339698D8E5073711A4EB4F6B4D306FCAB36DE4D05DAD3BC9E5C298CE0316B219C2
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: clicklife.clicklifeuae.ae
Sending IP: 64.64.4.134
From: SALES MANAGER <info@cgc-kw.com>
Reply-To: SALES MANAGER <info.cgc-kw@mail.com>
Subject: Product Inquiry - JP54 AVIATION KEROSENE COLONIAL GRADE AVIATION FUEL
Attachment: purchase Inquiry -pdf.zip (contains "purchase Inquiry -pdf.exe")

AgentTesla SMTP exfil server:
mail.hitechnocrats.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.AitInject
Status:
Malicious
First seen:
2020-06-10 11:46:08 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 8afe3c84880cd4faed0068712abe638b934f7e4799cd4beaf6dea4151e511272

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments