MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e84499dc9dd628f3a07ba386c534a7ee8fe59ec5d669d354604fe75094e8421. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8e84499dc9dd628f3a07ba386c534a7ee8fe59ec5d669d354604fe75094e8421
SHA3-384 hash: 118d95bdf710670a566ff5c90b55b73ea0402150d19f06efac864fcf51346cb3bf8647a9547ad194848ea756037b3501
SHA1 hash: d4f784a47ebeacae1946553f605436143a848f12
MD5 hash: 0fcf47f1b9316e3e687c02dc28b86d31
humanhash: coffee-purple-december-comet
File name:PRODUCT_DETAILS.PDF.gz
Download: download sample
Signature AgentTesla
File size:754'523 bytes
First seen:2020-08-03 13:53:52 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:MrzUbK5lrf8Tc/zuqojjCbO43EYrLFSjnmuUoxhnu6aspThEeKIIqP:MHUb+NqcXofslfFSjnggu6AqP
TLSH 66F42315D5F4A7CC4A80F5763B792488DCED103134F98E03A18E67F4826DBAFA9690F9
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: webmail.badhotelschevenigen.nl
Sending IP: 5.178.32.122
From: Leonel Martinex <leonel.martinex@badhotelscheveningen.nl>
Subject: Order
Attachment: PRODUCT_DETAILS.PDF.gz (contains "PRODUCT_DETAILS.PDF.exe")

AgentTesla FTP exfil server:
ftp.skibokshotell.no

AgentTesla FTP exfil user name:
brompl@skibokshotell.no

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Hacktool.Ymacco
Status:
Malicious
First seen:
2020-08-03 13:55:10 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 8e84499dc9dd628f3a07ba386c534a7ee8fe59ec5d669d354604fe75094e8421

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments