MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98e2c1550d05f77bc1d485e0bcdb3ac1b703441a395a1b91b40f5daaf01fc507. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 98e2c1550d05f77bc1d485e0bcdb3ac1b703441a395a1b91b40f5daaf01fc507
SHA3-384 hash: d73be9b02699db87238827525b93b9389041853622b9f3169bc5c612e483b27081ca87999cf236ccab33d942033d048a
SHA1 hash: 38218b381429bca364b6bd49d77dd3e5786edce5
MD5 hash: a9d192a45e18578b3a8212821525fd84
humanhash: jig-vermont-alaska-idaho
File name:Order 01001O02.zip
Download: download sample
Signature AgentTesla
File size:677'348 bytes
First seen:2020-10-12 07:33:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:d/FUcZTtT6LeFtXsgkRjuEO+Xu3XcZzIwCUC6rFUImBLjVZ:d9tF9pFNsgkR6R+WXcZMwCyZ+
TLSH D2E433D1B326E4A6F5726619E8FE3111B6A90E54BEF7BE1C80043AEE154338C05AFD53
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: aerial-properties.com
Sending IP: 96.125.165.96
From: Pablo Silvage <sales.bigfzabric@gmail.com>
Subject: Order 01001O02
Attachment: Order 01001O02.zip (contains "Order 01001O02.exe")

AgentTesla SMTP exfil server:
webmail.eurosets.pw:587

AgentTesla SMTP exfil email address:
euro@eurosets.pw

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 98e2c1550d05f77bc1d485e0bcdb3ac1b703441a395a1b91b40f5daaf01fc507

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments