MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5b6ecb209e926a7ac7b2acf919892087be3a2c3099f54d0142bc10a1cd8c145. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b5b6ecb209e926a7ac7b2acf919892087be3a2c3099f54d0142bc10a1cd8c145
SHA3-384 hash: 3392c7fe1ae832c379f7ec48341a75c99236434674bfdfb87d986eccecc4b759229af93b0e6ef4cf16f75c414345a6fe
SHA1 hash: 93f1f9ee4cf58bd07f443d21adadc8d0dade28c7
MD5 hash: 010ab9afee7f5d54aef88188fcf17bf3
humanhash: eighteen-october-venus-purple
File name:Prompt Payment for Invoice ~ Contract ~062020_PDF.rar
Download: download sample
Signature AgentTesla
File size:405'093 bytes
First seen:2020-06-08 06:06:49 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:aSJX4mtIJQwwWOgeDXCeTNGdvsMNvlnRpILJJoLE:LaQ8g7GdrvlnRpIfsE
TLSH D984238238F78C3C2426466E27C441BEE50A540DCB37E7D65ED39AA64C89F897DC6C1B
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.571.zizospanltd.casa
Sending IP: 167.71.234.243
From: Rocky Harris <Rocky.harris@defra.gsi.gov.uk>
Reply-To: ev.cayenne@outlook.com
Subject: Re: Prompt Payment for Invoice ~ Contract ~ 06/2020
Attachment: Prompt Payment for Invoice ~ Contract ~ 062020_PDF.rar (contains "Prompt Payment for Invoice ~ Contract ~ 062020_PDF.exe")

AgentTesla SMTP exfil server:
smtp.shyuanhzimeng.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-08 06:08:06 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b5b6ecb209e926a7ac7b2acf919892087be3a2c3099f54d0142bc10a1cd8c145

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments