MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99824aa9c82c101ead1b3d7c8371c2922f427148fe816ff8cdd8bbbf9c42c903. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 99824aa9c82c101ead1b3d7c8371c2922f427148fe816ff8cdd8bbbf9c42c903
SHA3-384 hash: f2116aa5331aec7dc3102947a5b22e6a2876164103757231ba128ab4573804855f612da33595636a763db750492fb4fc
SHA1 hash: 24eead828d46fc45739f200da456d45eec820eb8
MD5 hash: 17b8d2a12efdeeb7af979582b5f10cd4
humanhash: batman-golf-romeo-angel
File name:Disc FDBC 3660.rar
Download: download sample
Signature AgentTesla
File size:375'527 bytes
First seen:2020-07-09 18:23:30 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:xQEqBv3znTKiNUP8HZGa8LKpYKNZVQ3DTI3p3s3/m9W3MgqkFLqR1rYiqLOpVVpa:xQEqBvHZGTKrm68vm9eMgqkFLclTVPU
TLSH FD842367E429AEA541BAC5AD3DC8BC9609E52AF703C670089D5A420F3F47DD3CA6D1C1
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fax.local
Sending IP: 118.99.229.12
From: Chia Hui Trading Co <info@chia-hui.com.tw>
Subject: SWIFT messages
Attachment: Disc FDBC 3660.rar (contains "Disc FDBC 3660.exe")

AgentTesla SMTP exfil server:
mail.coolgirlsnation.com:25

AgentTesla SMTP exfil email address:
ala@coolgirlsnation.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-09 18:25:05 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 99824aa9c82c101ead1b3d7c8371c2922f427148fe816ff8cdd8bbbf9c42c903

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments