MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0485c8b53dff1509e62e1aff5b0f73cae7078c9d51f02361ec3a85677d80f86. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b0485c8b53dff1509e62e1aff5b0f73cae7078c9d51f02361ec3a85677d80f86
SHA3-384 hash: 1e86728bf54e10087890b0f8d9d19085c31463f80d250c2dce7cf9da6014a1dd98a0c2fcb0f9decf335dc79a55a8155f
SHA1 hash: ddf0d92a251a30f389aad8d833395233453d89df
MD5 hash: a73d83f5a34ddb0981aa3632286fc137
humanhash: alanine-eighteen-monkey-angel
File name:M00058.rar
Download: download sample
Signature AgentTesla
File size:472'631 bytes
First seen:2020-08-19 14:15:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:00bZEStURVJK5Gbre1i4KvpCtmPDhGKRJnw:00Xt+VM5li4KYmPvR9w
TLSH 10A4234CF32440BCB1AC0BC451D80D72E297348A1F198FB25B792EA22D67745F6E6D66
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.btjlines.com
Sending IP: 137.59.125.189
From: Accounts - C & C Marine Combine <accounts@ccmarine.in>
Subject: RE: C&C INVOICES / OPS / PAYMENT SCHEDULE - TOTAL CNC PENDING FOR HT APPROVAL 18082020
Attachment: M00058.rar (contains "M00058.exe")

AgentTesla SMTP exfil server:
smtp.israelagroconsultant.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-19 14:17:04 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b0485c8b53dff1509e62e1aff5b0f73cae7078c9d51f02361ec3a85677d80f86

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments