MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3c6051103020a9d10666012a5709036ec080a9af6f3afee4e22c668d005a70e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b3c6051103020a9d10666012a5709036ec080a9af6f3afee4e22c668d005a70e
SHA3-384 hash: da000dabfa9916d1f489733f74b2c41c43c1ee33d0b1565e7f3f0c9b92545abb1657029d65a7c815eb25c9ead95ac187
SHA1 hash: 94ec6ef39b4ea5c92aec42be23b0dcea9a93f470
MD5 hash: b2f8e3a1a4c9d7889009d78a09e52b24
humanhash: winter-lemon-december-sad
File name:Invoice.rar
Download: download sample
Signature AgentTesla
File size:4'851'321 bytes
First seen:2020-07-07 08:51:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 98304:svNVi3n8l+iPCNJ3pLceXHduK9MT0w51+pbCh2MVeZlBN6mkDX8To5i66a:ESnGVmLH/9Dw51+pbCPGBgbDX8TV66a
TLSH 042633F0E1CAC1499F70FD3AB899AD943018F21716CE12296F8DCAA21D446BDFD9187D
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.pickelhost.com
Sending IP: 185.183.98.177
From: Harrison Contractors<contact@ariapetrolub.fun>
Subject: Re: R: R: Order Confirmation Nr. 2748 of 20102/2020
Attachment: Invoice.rar (contains "Invoice.exe")

AgentTesla SMTP exfil server:
smtp.harrisioncontractors.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-07-07 08:53:04 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b3c6051103020a9d10666012a5709036ec080a9af6f3afee4e22c668d005a70e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments