MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0d2d5dad6b7da4a1b0d62f0788ad1fa2ba76cd472a1a29e4f547983a1f10e5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b0d2d5dad6b7da4a1b0d62f0788ad1fa2ba76cd472a1a29e4f547983a1f10e5a
SHA3-384 hash: d257c8749a6ab333d5e1988802847deefa055b0fd1104bcbeaf1c7ac6b4c120a5eca00908a80d705cc2d05c9e978f5ec
SHA1 hash: 8b0e153ce094d6ce3a82e21a4ea624284ce216b2
MD5 hash: 2e4f66809274f059ff04173353930251
humanhash: nineteen-high-tennessee-uncle
File name:PO 76754321.rar
Download: download sample
Signature AgentTesla
File size:928'877 bytes
First seen:2020-06-03 10:49:26 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:ReaT8Egx1pOjD0E4A8gJlUXDKOH8KBgQS8D:R7Yhx1NwKDhHVBXS8D
TLSH 8715332668AA18F7EB400D27337945B5E60F33373D49B132DAD36691711ACDCA40ABF8
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: d005i9-dellanesta.sphostserver.com
Sending IP: 185.81.1.98
From: gabriele@fabianelli.it
Subject: AW: ORDER FOR SHIPMENT TO LEBANON
Attachment: PO 76754321.rar (contains "PO 76754321#.exe")

AgentTesla SMTP exfil server:
mail.shamdew.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 11:03:18 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
14 of 31 (45.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b0d2d5dad6b7da4a1b0d62f0788ad1fa2ba76cd472a1a29e4f547983a1f10e5a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments