MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0bf14d6b3484e4f60f4d8861ef11334159f1174800a3ac7a86ee25db563a4a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a0bf14d6b3484e4f60f4d8861ef11334159f1174800a3ac7a86ee25db563a4a9
SHA3-384 hash: 6e38b6674d16f417926b1dc011f52ec106750bbf73c9b3a2b1cabfbd63d9379722bcf77913116f6beda0a244678912a4
SHA1 hash: 86504070fa9bd2c8b6cac5008aa3185155af142c
MD5 hash: e2545d337582edd92318c81209d7ec32
humanhash: coffee-alanine-neptune-ohio
File name:PO No. 104393019_pdf.gz
Download: download sample
Signature AgentTesla
File size:549'717 bytes
First seen:2020-12-03 08:35:39 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:qjdXzX2rGS9jhu8U/MnfFSYpvhT1ulyKa/RAicPQiMajc2ZQiZ21ZdXkPEq5F:WdjXzwjBUEnNR5hT1ukKLQiMa9VZ21Dm
TLSH 9AC423077A57CAF1A553AFE93AE04F771EDF740BD503862FAB92B2A5CF054469074090
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.palmercreative.co.uk
Sending IP: 185.217.43.142
From: Bahr Muhammad <info@albahralarabi.com>
Subject: URGENT PURCHASE ORDER No. 959309292
Attachment: PO No. 104393019_pdf.gz (contains "PO No. 104393019_pdf.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
127
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-03 08:36:06 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz a0bf14d6b3484e4f60f4d8861ef11334159f1174800a3ac7a86ee25db563a4a9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments