MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c088fe4ce0f9df55633f922c95d28ae63e67d81ef86ce9c89a97a9ae2a7daf94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c088fe4ce0f9df55633f922c95d28ae63e67d81ef86ce9c89a97a9ae2a7daf94
SHA3-384 hash: 57db3afd111d72d4037ae0b6ed8a6f7916a74c96faa9b060181f8468e7e13dede4b9f0eedf5db4b100ed64a4e6691a00
SHA1 hash: 6ae1bde4c49708a0f6acebf5b8112adbc5dc9107
MD5 hash: 6daa83b5c52610f9b74f2d807fed9ad2
humanhash: jersey-sixteen-colorado-iowa
File name:Bank Details.uue
Download: download sample
Signature AgentTesla
File size:954'616 bytes
First seen:2020-07-21 18:42:57 UTC
Last seen:Never
File type: uue
MIME type:application/x-rar
ssdeep 24576:ybUGmJplKPqp4R6Az+Wr2VmfNsw7udUBqusbyM9:ybUGApgx1x+6YeqR9
TLSH ED153353F474F87FAE9D25252EAA546871C0818DB28F88D4036B4C01EDAFA5BF25173B
Reporter abuse_ch
Tags:AgentTesla uue Yahoo


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic302-3.consmr.mail.bf2.yahoo.com
Sending IP: 74.6.135.42
From: Sales manager <markwu586@yahoo.com>
Reply-To: Sales manager <markwu586@yahoo.com>
Subject: Fw: Payment Slip
Attachment: Bank Details.uue (contains "Bank Details.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-21 18:44:10 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

uue c088fe4ce0f9df55633f922c95d28ae63e67d81ef86ce9c89a97a9ae2a7daf94

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments