MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0e5eb354328d092bf24c39f59cffa05f1c05eb98f9784d518876de190e70c14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b0e5eb354328d092bf24c39f59cffa05f1c05eb98f9784d518876de190e70c14
SHA3-384 hash: b45f27e646b0ef7081879ac5bd759066ba33b84dc222ae1cf43f3f4679d4e2539efedb5d74fbdf527a21e995dec8d568
SHA1 hash: 45698fc3e4a05cde1a783846dbd3d5ac37b24025
MD5 hash: 6ecc9f0959205c43c985e057e2e7940f
humanhash: ohio-pennsylvania-november-london
File name:E.T.A Shpmts_xlsx.rar
Download: download sample
Signature AgentTesla
File size:320'438 bytes
First seen:2020-06-08 06:51:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:eZ3tcr4q3J+M7R2nR6o+c+/diO9mpW22G82IQgpMV8YyRSU2YNqAv/EUu4YPX:eZ3tcmMFO6o+//diO9F22G8bG8YyRSUc
TLSH 9B6422C6E001AF5A0F592B5BD75F2A6AED05923C84F983D70B30C7DE4A328E6D520759
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: jbcexpress.com
Sending IP: 176.123.7.54
From: JBC Express Freight LLC - Pawan Kotian <mctacc7@jbcexpress.com>
Reply-To: JBC Express Freight LLC - Pawan Kotian <adeshbjrla@gmail.com>
Subject: FW: BOOKING SHIPMENTS / ETA
Attachment: E.T.A Shpmts_xlsx.rar (contains "E.T.A Shpmts_xlsx.exe")

AgentTesla SMTP exfil server:
mail.nabf.com.au:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-08 06:53:03 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b0e5eb354328d092bf24c39f59cffa05f1c05eb98f9784d518876de190e70c14

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments