MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad80aa591624fdb726f815f9e18da8ddfd38d1486c11c18cc1bceac86e52c061. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ad80aa591624fdb726f815f9e18da8ddfd38d1486c11c18cc1bceac86e52c061
SHA3-384 hash: b518bd8e0dc16197b02abe2c000c7b1453e5ef6ab766f4592d22fefe0c4cf6f1d29d75e02dfa5793d49c99e929841fc5
SHA1 hash: 3c619d04f2fc2887ad405be0f9c54448d9b8e3d4
MD5 hash: 531b5765517299052e2a554dd12ad48b
humanhash: oranges-comet-juliet-seven
File name:Scan doc.6.pdf 877.6.gz
Download: download sample
Signature AgentTesla
File size:496'828 bytes
First seen:2020-08-19 07:09:45 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:1AbygakR4vWiNuO8V+IsyxeukDDnzGe+oDJ/qzx7i:mhR4emuPtW/nzogczx7i
TLSH 56B42302489D80DEE8C5A876169DF9A19FB7E4C29DD3C105564AC1336F4BF2B8472CBB
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.dphe.gov.bd
Sending IP: 203.202.246.122
From: ee.sirajganj@dphe.gov.bd <ee.sirajganj@dphe.gov.bd>
Subject: Document Tested
Attachment: Scan doc.6.pdf 877.6.gz (contains "Scan doc.6.pdf (877.6.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:5987

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.CryptInject
Status:
Malicious
First seen:
2020-08-19 07:11:05 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz ad80aa591624fdb726f815f9e18da8ddfd38d1486c11c18cc1bceac86e52c061

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments