MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93b3511688fc0339d0dd540510b5e4b3d71aa78d5938c918c73c18ca6c27bd81. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 93b3511688fc0339d0dd540510b5e4b3d71aa78d5938c918c73c18ca6c27bd81
SHA3-384 hash: f68c0e4e223eb844fa168cd4dbc051927ad97166a1204621f848c51937431d3854445af8ae799f9801cde11377ad1060
SHA1 hash: b143da67ced981f0f1212342d76f9f0b4c0476e4
MD5 hash: fbb6a4f1970a627b9e8878f795fe7b12
humanhash: cold-pennsylvania-grey-hot
File name:009903930030.GZ
Download: download sample
Signature AgentTesla
File size:374'184 bytes
First seen:2020-06-22 18:48:05 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:AXdOlx2GsQvgZO1sd0tkqFse/3sEAQt6F0a6c4kTcrRLcc3YUuQ9/O8xrMbZ:AX8SGsQvgZO1sWt88t1kn6yOR4c36S/u
TLSH 788423ACC69C2B85DAAB322C038C91DD49B1CD728B64E3ADD204C6B56CD8FF415578DB
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmx.net
Sending IP: 185.222.58.143
From: Prasad Poojari,.<sharad.trivedi@gmx.net>
Subject: Re: Re: AW: PI for Order9387-34
Attachment: 009903930030.GZ (contains "009903930030.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-22 18:37:00 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 93b3511688fc0339d0dd540510b5e4b3d71aa78d5938c918c73c18ca6c27bd81

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments