MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8d268276ecc97a5a5816771f0f15120a177b3cc3422889abb43e8b686429bdc7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8d268276ecc97a5a5816771f0f15120a177b3cc3422889abb43e8b686429bdc7
SHA3-384 hash: 27c98db0953defc92f3b1925e52d056054c688a459c9b4f1bc768d51eec5f1493f6084850991f46bd60f2528115f93ac
SHA1 hash: 0dbf40627c928ea40ded6a2f50f89a967b9fc259
MD5 hash: 13b72bbe142c88171dfe067bd315fa23
humanhash: harry-ceiling-tennessee-hot
File name:Equipments_order.001
Download: download sample
Signature AgentTesla
File size:443'556 bytes
First seen:2020-04-03 11:25:18 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:/OpqUqbKYoqIduiOerpHJNF/SZIqkSNS6nHp9n7ClRo/b:2BPYoLjOeFpNwZIqkSNzrERoz
TLSH EB942385BE588BDDD2703F57BCEF19D9F472DC116A05C1E4626C7AD02EC1CABA988C24
Reporter abuse_ch
Tags:AgentTesla COVID-19 r001


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: men.com
Sending IP: 217.61.97.173
From: Charlie Cliff <fin@nagle.gq>
Subject: Re:Covid-19 Equipment Order
Attachment: Equipments_order.001 (contains "cure_order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587 (77.88.21.158)

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Loki
Status:
Malicious
First seen:
2020-04-02 23:03:47 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
15 of 47 (31.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8d268276ecc97a5a5816771f0f15120a177b3cc3422889abb43e8b686429bdc7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments