MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d15000a5e83152412aa6435b234daa6c686ab80c64bea576284541b32b67408. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9d15000a5e83152412aa6435b234daa6c686ab80c64bea576284541b32b67408
SHA3-384 hash: 7ac80232b1d6dea1b34842b6a50d23136762da57ddd5375f9ab8b0a32ffc1ff197de991dee71328ae8fe36635c6524d0
SHA1 hash: db4ae87ef10c6254d702d4114a2e13a1d71e7874
MD5 hash: ad9a5f1a6d47aa95fcecf6894ead3c5c
humanhash: jupiter-beer-hawaii-fruit
File name:order list.arj
Download: download sample
Signature AgentTesla
File size:391'307 bytes
First seen:2020-06-19 13:55:13 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:3l/TDA3ueik6vhlS2gpXgeFWfOEVOXnLEK240+X/ljCr1PoLccHr3DMKCoewLNj9:VLuyNLClkI4K9oBGcMc5Aykb
TLSH 508423C62C55626D2C09907E2B278F965D6F7D862C63D6EBF31A3407280C5A22770DFA
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: serve0.lumoss23.pw
Sending IP: 142.11.213.201
From: Mr. Jose Landeros <hr@lumoss23.pw>
Reply-To: francesco.giordano@giaguarospa.com
Subject: New Order
Attachment: order list.arj (contains "order list.exe")

AgentTesla SMTP exfil server:
mail.navarronavarrosl.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-19 13:57:03 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 9d15000a5e83152412aa6435b234daa6c686ab80c64bea576284541b32b67408

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments