MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6aa8a29fbf97179b1187b3c4c55ef20afd67144d67ec91a7860c4675933ea65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a6aa8a29fbf97179b1187b3c4c55ef20afd67144d67ec91a7860c4675933ea65
SHA3-384 hash: 861a2ac61eb9590e8bdc4ecc57f7bb17eefd32c5c7e8e301586895175c09fce9cc41c86ce1834306b15ac0de75ceccea
SHA1 hash: e5c23d479971e6d8910267cd6fdc9adf88157238
MD5 hash: ab1453ba2435e6b2c554457f016c897c
humanhash: orange-east-earth-hot
File name:IMEGUISA CONRACK S.L PEDIDO 6110 03072020.r00
Download: download sample
Signature AgentTesla
File size:326'190 bytes
First seen:2020-07-03 12:23:40 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:NcdBP56xoklbDtjOnVDqDP/zPIUdZPGXUsMnXHYdVVbR501ETyVFBb:Kdr6CKHt6nVDiPGUVXHY/L5011VFd
TLSH 9E6423800FBEF0DF6889835FDF5AE341A1164BA504DB2625F507A6ED75F924138E438E
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: web30.assec.net
Sending IP: 207.154.216.246
From: Rocio lazaro <rocio.lazaro@imeguisa.com>
Subject: RV: Pedido No.6110 - IMEGUISA - CONRACK S.L. 03.07.2020
Attachment: IMEGUISA CONRACK S.L PEDIDO 6110 03072020.r00 (contains "Orden Compra No.6110 03072020.exe")

AgentTesla SMTP exfil server:
mail.corroshield.co.id:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-03 12:25:07 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 a6aa8a29fbf97179b1187b3c4c55ef20afd67144d67ec91a7860c4675933ea65

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments