MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8e7235222b59eb02eb7fb533e80d6cb2482611bd9afe148e03f3c208bd09d88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b8e7235222b59eb02eb7fb533e80d6cb2482611bd9afe148e03f3c208bd09d88
SHA3-384 hash: b57c83895ba44d6ba4d533b8777dddab10eeb29a59fa6eab5d0e4668dd2bbaac3ba24e789cc2b3b9f6d02f1bdb053dcd
SHA1 hash: 2354be5c5dab9022388254e93147be888165d003
MD5 hash: 68c9679b44ac8c6f286c5d5d0abac379
humanhash: nebraska-montana-alaska-mississippi
File name:Order.001
Download: download sample
Signature AgentTesla
File size:221'942 bytes
First seen:2021-03-22 07:40:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:C2f8j09J7B6tFIXSUcez6H/QGFn6T59NhR:CA/9J7B6jIXSUcb/XMr/
TLSH C9242360378EBD1BB086F6824BC0C486A761F617E917AB4B34055A316D19CBDBCD7F88
Reporter abuse_ch
Tags:001 AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: makelove.ddnsgeek.com
Sending IP: 103.20.235.117
From: Dave Richter <info@linkbuild.me>
Subject: URGENT ORDER!
Attachment: Order.001 (contains "Order.exe")

AgentTesla SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2021-03-22 07:41:16 UTC
AV detection:
11 of 47 (23.40%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b8e7235222b59eb02eb7fb533e80d6cb2482611bd9afe148e03f3c208bd09d88

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments