MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8954e0e9bbcba4e8aaf123b30d5ac875a8f6735988a9b5fd98e91a83b997b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a8954e0e9bbcba4e8aaf123b30d5ac875a8f6735988a9b5fd98e91a83b997b2f
SHA3-384 hash: 61bd9f1d254584c6f675a7ec4a31a61ed24303965e66308f00babf5f3718634522fddb68fb70fbde086c104ba5c692d7
SHA1 hash: 73db5a4f282f4b13aa7811cf6a88bf0c55bdcf60
MD5 hash: f74a4294b7bf57030f8969e4f5f9b326
humanhash: pennsylvania-seven-fruit-neptune
File name:PO200513DCC025R-1.7z
Download: download sample
Signature AgentTesla
File size:561'502 bytes
First seen:2020-07-11 06:03:12 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:PRYn6s+qRMoNytF/OdrGKHvriudqAV2OZyt8mMZ2qV:PRYn63cytp83Hzj3AtBo2E
TLSH 00C42346209994878BCEF04C16C3C53D5C0B9802B3DEB918A376B36F9E35D9A778B794
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: petrit.best
Sending IP: 104.129.0.123
From: Angeles Ureta <angeles.ureta@airesgifts.cl>
Subject: BISSELL INTERNATIONAL - PO#200513DCC025R-1
Attachment: PO200513DCC025R-1.7z (contains "PO#200513DCC025R-1.exe")

AgentTesla SMTP exfil server:
mail.daiphatfood.com.vn:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-11 06:05:05 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z a8954e0e9bbcba4e8aaf123b30d5ac875a8f6735988a9b5fd98e91a83b997b2f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments