MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c591a23b66a8f18bed2afda0963673dc93574889fa468158f39fc110203fdf1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c591a23b66a8f18bed2afda0963673dc93574889fa468158f39fc110203fdf1a
SHA3-384 hash: 4d2c3a7ec905ccb8a5bf9582b9586bf0457ae7d1d7ff7a5072de4c385c08a0911b2536a8eab0e128159b5d3cf5f5ff93
SHA1 hash: 893b373b40310acfc4d9d1da7dd57bca2f37a8a1
MD5 hash: ab83dd24f63ea06c1d1bea5914ea6c1d
humanhash: lima-muppet-hydrogen-island
File name:New Quotation.zip
Download: download sample
Signature AgentTesla
File size:1'379'031 bytes
First seen:2020-05-08 04:19:54 UTC
Last seen:2020-05-11 21:00:34 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:am4HXoOPc5/ru2XPkEZ6ktHe2CV/xAAN9icNqif4JAcNME4kzMTcppcraQW:aTYBPR6kte2CV/S6h4iwC64TcbUtW
TLSH CD553381C2C18A42BAF6E5C0FBFB4F9DC25517EBE1C7DF5796136089B5DC0A2252423A
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email
From: Ali Albayrak <gurgaon@dentalavenue.net>
Received: from server.adityainfotech.net (server.adityainfotech.net [108.170.48.90])
Date: Fri, 08 May 2020 06:33:44 +0530
Subject: URGENT NEW ORDER- PO. 48097 TARROS COMPANY PROJECT
Attachment: New Quotation.zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-07 23:07:03 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c591a23b66a8f18bed2afda0963673dc93574889fa468158f39fc110203fdf1a

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments