MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8e84499dc9dd628f3a07ba386c534a7ee8fe59ec5d669d354604fe75094e8421. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 8e84499dc9dd628f3a07ba386c534a7ee8fe59ec5d669d354604fe75094e8421 |
|---|---|
| SHA3-384 hash: | 118d95bdf710670a566ff5c90b55b73ea0402150d19f06efac864fcf51346cb3bf8647a9547ad194848ea756037b3501 |
| SHA1 hash: | d4f784a47ebeacae1946553f605436143a848f12 |
| MD5 hash: | 0fcf47f1b9316e3e687c02dc28b86d31 |
| humanhash: | coffee-purple-december-comet |
| File name: | PRODUCT_DETAILS.PDF.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 754'523 bytes |
| First seen: | 2020-08-03 13:53:52 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:MrzUbK5lrf8Tc/zuqojjCbO43EYrLFSjnmuUoxhnu6aspThEeKIIqP:MHUb+NqcXofslfFSjnggu6AqP |
| TLSH | 66F42315D5F4A7CC4A80F5763B792488DCED103134F98E03A18E67F4826DBAFA9690F9 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: webmail.badhotelschevenigen.nl
Sending IP: 5.178.32.122
From: Leonel Martinex <leonel.martinex@badhotelscheveningen.nl>
Subject: Order
Attachment: PRODUCT_DETAILS.PDF.gz (contains "PRODUCT_DETAILS.PDF.exe")
AgentTesla FTP exfil server:
ftp.skibokshotell.no
AgentTesla FTP exfil user name:
brompl@skibokshotell.no
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Hacktool.Ymacco
Status:
Malicious
First seen:
2020-08-03 13:55:10 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
1/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.