MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b3006b8ee2a36526f3c143d4f67d52f844538af9b41550b2ddf4e0c810459b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9b3006b8ee2a36526f3c143d4f67d52f844538af9b41550b2ddf4e0c810459b1
SHA3-384 hash: e3988da6b8d63cf5d1106b79ed187e9a9ce9384b091845a3e2879c93405b62725feb1ded69c06373b57ccd1067f533aa
SHA1 hash: 16750b65715b47dbf4a1b0c6f70746219119b1d9
MD5 hash: 95f190bb9c139f7fe294219d095a1364
humanhash: quebec-oscar-spring-texas
File name:Tekrarlanan Siparis 28102019.pdf.uue
Download: download sample
Signature AgentTesla
File size:268'667 bytes
First seen:2020-06-16 12:17:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:tw404gap3lsWCQfJNHwqSuurEujfw1czh6kPLS7+:twVaJOkNQzrE0rzgQ
TLSH 5C442336902D4682C95FD03A9BBED69ADB1E5EA201C2FD71F94C8656B7DE06CC038817
Reporter abuse_ch
Tags:AgentTesla uue


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: eldem.com.tr
Sending IP: 156.96.62.208
From: Hassan Lilly <aatalar@eldem.com.tr>
Subject: Tekrarlanan Siparis 28102019
Attachment: Tekrarlanan Siparis 28102019.pdf.uue (contains "Tekrarlanan Siparis 28102019.pdf.exe")

AgentTesla SMTP exfil server:
mail.bestinjectionmachines.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-16 12:19:05 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9b3006b8ee2a36526f3c143d4f67d52f844538af9b41550b2ddf4e0c810459b1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments