MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf32e2335e5e22c658bc4314b2825661300b583dc3b66248a79235c06eb711fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bf32e2335e5e22c658bc4314b2825661300b583dc3b66248a79235c06eb711fa
SHA3-384 hash: c32f1c9999aaf4c062fadced8e0dc8e2466ce55c9741bf22967647c8a9fa730a18377bf62d2bb81badd1d290e771f22a
SHA1 hash: f9abcbaeb6c2d9379b66c3434b0b95d5cf1c7e8b
MD5 hash: f717dc561728a5509cf1f4e9ef7e25ae
humanhash: red-purple-alabama-west
File name:Microsoft.zip
Download: download sample
Signature AgentTesla
File size:307'928 bytes
First seen:2020-08-08 17:59:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:l1nXstBkWAHgUOe4aRgABjNOoWPH+OQsNgNN4sXPUdfb5pPNJ:EtBNA0Bp6Ot+OQLNN4s83pP3
TLSH E1642366FA2392032C1B54BEFD34688273AE08F85C10ED112BEA9D7B2F15DD4CD64E65
Reporter abuse_ch
Tags:AgentTesla Outlook zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: EUR02-AM5-obe.outbound.protection.outlook.com
Sending IP: 40.92.67.22
From: beatrice dizy <dizys2@msn.com>
Subject: IMPORTANT NOTICE
Attachment: Microsoft.zip (contains "Microsoft.exe")

AgentTesla SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Pretoria
Status:
Malicious
First seen:
2020-08-08 18:01:05 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip bf32e2335e5e22c658bc4314b2825661300b583dc3b66248a79235c06eb711fa

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments