MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92204246a210d1b3762540b1d5df1ed0807fd26d76825cca72de3f643a2cc7e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92204246a210d1b3762540b1d5df1ed0807fd26d76825cca72de3f643a2cc7e0
SHA3-384 hash: d8fa1c43a2d3e74a0b7d7e8122bf974c14244e5930bd223f71bcd714987bfa076a7e8c2aac0f301391901067bea6a640
SHA1 hash: a9840e53f4e0ed1b031fbe2445f8296278eafc20
MD5 hash: bb9829a2d91fe249bacd5463e60b6cf7
humanhash: iowa-iowa-carpet-single
File name:MED_05112221997_88794pdf.zip
Download: download sample
Signature AgentTesla
File size:461'653 bytes
First seen:2020-05-06 17:45:11 UTC
Last seen:2020-05-11 20:59:29 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:VSqIKh3DlytajHdH5Lg8uJPAGCCLfd+brm1c7s8nt1qZu:Vv33xZcvZAGJVH2qk
TLSH 70A4232A484220EEB9ABC5246A0DF8AFE05185B3199FF90F841D1FAF453E4C97B44FD5
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: eazymail.cloudissp.com
Sending IP: 202.6.21.19
From: Баширов Рафаиль Рамильевич <d.opacak@bistradoo.hr>
Subject: URGENT: MED ORDER / B-051122 /Invoice & Specs
Attachment: MED_05112221997_88794pdf.zip (contains "MED_05112221997_88794pdf.exe")

AgentTesla SMTP exfil server:
vietnhon.com

AgentTesla SMTP exfil email address:
trungtran@vietnhon.com

Intelligence


File Origin
# of uploads :
2
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Noon
Status:
Malicious
First seen:
2020-05-06 21:11:22 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
30 of 48 (62.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 92204246a210d1b3762540b1d5df1ed0807fd26d76825cca72de3f643a2cc7e0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments