MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c85c5fd6257987d4386a8592e254eee58bcc3d8b7a0f8d7d2e4f7f8b5ef23f98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c85c5fd6257987d4386a8592e254eee58bcc3d8b7a0f8d7d2e4f7f8b5ef23f98
SHA3-384 hash: c335865c4965b6a6f7b0bb83670d9ef5916063dd7a7666b5547ae64b940aabafa3f30be144a0d45cfc5cfe235fc6e059
SHA1 hash: 40011dad7f77e746b1401907b5b0e52ae3a3eaec
MD5 hash: 8fc2871a91b48d1ae904d9eadb666427
humanhash: batman-wisconsin-lactose-north
File name:RETENCIONES.CAB
Download: download sample
Signature AgentTesla
File size:281'694 bytes
First seen:2020-05-20 11:57:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:WeYFloQAYRAVV5zc0snOIwkAErX4GP97/ALJ82:qFlpAZV5zcsdVErXJP9kz
TLSH 0054231783373ACC93E19A0A4462A4C86B767D08675BAD1362D20D2064D399FCEFF6F0
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: eepsjc1-02.nexcess.net
Sending IP: 104.207.238.163
From: pagos diarco <no-reply@diarco.com.ar>
Reply-To: jonah@briistol.com
Subject: Diarco - Orden de Pago
Attachment: RETENCIONES.CAB (contains "RETENCIONES.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Androm
Status:
Malicious
First seen:
2020-05-20 12:35:58 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
18 of 47 (38.30%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c85c5fd6257987d4386a8592e254eee58bcc3d8b7a0f8d7d2e4f7f8b5ef23f98

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments