MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7917f132ab21372589f4677e6149d58202bf135e4d0bb0a744bb64c7cba5a70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a7917f132ab21372589f4677e6149d58202bf135e4d0bb0a744bb64c7cba5a70
SHA3-384 hash: 25fe29ef67643d038b36b1a00a70faaab5783f02a0fc1bbd0a92cefc344e69594bbc0a11c62d1e700499d003d81b91ee
SHA1 hash: bf6ce1ec59f5ad2b3ae0cffb7c8c2269cd4a2a3d
MD5 hash: e1dfd5c767ff34711be06967b50b7d20
humanhash: oklahoma-september-florida-cold
File name:Scan doc.rar
Download: download sample
Signature AgentTesla
File size:433'762 bytes
First seen:2020-07-07 09:43:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:cRRNST/nwm9KiH/IBcH2wHbdYIafzkd204RomRltr3ZT1c9C6ei0LOHpnN:2EnRKiIBcifzi4jZT1b6V0LYnN
TLSH AE9423350A6C20D43EF8C6FB9ABE8D2F67C73A5171277BA58CA825481D5609D1F35B80
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pro21.emailserver.vn
Sending IP: 103.15.48.241
From: Liu Dan <lytt@newbev.vn>
Subject: Urgent updated Purchase Order
Attachment: Scan doc.rar (contains "Scan doc.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injuke
Status:
Malicious
First seen:
2020-07-07 09:45:09 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar a7917f132ab21372589f4677e6149d58202bf135e4d0bb0a744bb64c7cba5a70

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments