MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ba3f294111b0c0e6d43a1d997ebdea1b224478100bb31951a90fd3c40094368f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | ba3f294111b0c0e6d43a1d997ebdea1b224478100bb31951a90fd3c40094368f |
|---|---|
| SHA3-384 hash: | f3850ec246fbfa3a4a0b3d6bac884d9571110fb5d982d7d5167fd2649b36a145eaaa7d58cd4385beec8436eb0c3dedf4 |
| SHA1 hash: | dfe036104349124f13d14368375180d667178ab3 |
| MD5 hash: | 83bf776efcc054cf41b33c086330e4cc |
| humanhash: | jig-hamper-zebra-nineteen |
| File name: | DLR20-530 PO WH 5409- Umm Al Hayman EPC Project.pdf.lzh |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 713'787 bytes |
| First seen: | 2020-12-20 12:08:35 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:+bQ0zhZUXcksx3Mmef6GrvXDsppsmyKvshpgXuLQYJ4VmEXg8avArN+iM9/2l+AN:+Q6eX/sqf6OXDsX9shpgBHQ8avVF2lwA |
| TLSH | E1E423CD70ED003B78FF6652CD6AA59468F0F44215E81BF78F492412B1BAA2DB87C947 |
| Reporter | |
| Tags: | AgentTesla lzh |
abuse_ch
Malspam distributing AgentTesla:HELO: park-mx.above.com
Sending IP: 103.224.212.34
From: Khalid Parkar - Alhasawi Group <khalid.parkar@alhasawi.com>
Subject: RE: Purchase Order for Umm Al Hayman EPC Project (2020- 12- 233,230)
Attachment: DLR20-530 PO WH 5409- Umm Al Hayman EPC Project.pdf.lzh (contains "Purchase Order & DWG data sheet Compliance form PO WH 5409.exe")
AgentTesla SMTP exfil server:
mail.jk-peru.com:587
AgentTesla SMTP exfil email address:
johnmuller1922@gmail.com
Intelligence
File Origin
# of uploads :
1
# of downloads :
196
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Gathering data
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-20 12:09:07 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.