SHA256 hash: 92b3287ca777166f9231da535aa5248d3508ffdae60a53e378316ac079b9b60c
SHA3-384 hash: 13b7edebcb634b2b25644f2de61c2b58a8457c8a0f30175f3f1b608218c7f54927f050158db9d9007a8666327da221ff
SHA1 hash: 58f0225b257725c93f41e92a471d2a2f07029982
MD5 hash: 2914288341a628164f4288c3ac01c7e2
humanhash: tennis-london-fillet-network
File name:Proof of payment.exe
Signature AgentTesla
File size:623'104 bytes
First seen:2020-06-30 12:44:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744
ssdeep 3072:qcACBa5AWDPAJqBDzk+PjB9hagkcX4tOO67NpoutjEoUS3JS5kvz0jNyWCfnfbjV:qJfrBV19hz00NpoyjRUSk5kveyW8nje
TLSH BDD4E9133A1CE114CF9D9B37B5A60772E329B8AD7222839A1CBE73140C7BA773D511A5
Reporter @abuse_ch
Tags:AgentTesla exe

Malspam distributing AgentTesla:

Sending IP:
From: Mark Bradfield <>
Reply-To: Mark Bradfield <>
Subject: RE: Proof of payment
Attachment: Proof of (contains "Proof of payment.exe")

AgentTesla SMTP exfil server:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 25
Origin country US US
CAPE Sandbox Detection:AgentTeslaV2
CERT.PL MWDB Detection:agenttesla
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 10:09:00 UTC
AV detection:16 of 30 (53.33%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
Hatching Triage Score:   10/10
Malware Family:agenttesla
Tags:spyware keylogger trojan stealer family:agenttesla
VirusTotal:Virustotal results 25.00%

Yara Signatures

Rule name:Agenttesla_type2
Author:JPCERT/CC Incident Response Group
Description:detect Agenttesla in memory
Reference:internal research
Rule name:CAP_HookExKeylogger
Author:Brian C. Bell -- @biebsmalwareguy
Rule name:win_agent_tesla_w1
Description:Detect Agent Tesla based on common .NET code sequences

File information

Delivery method
Distributed via e-mail attachment