MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9ed65f3e8b2c3e76cbde4e0beb836eaa6b830aed07f1fcd9d3de089de350b1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c9ed65f3e8b2c3e76cbde4e0beb836eaa6b830aed07f1fcd9d3de089de350b1f
SHA3-384 hash: e71686894ec43ad6786a59dd522f16e356b320373ae9b06ebf17cb85821e43ea6a74d73678b011f19d640bf181c2ed93
SHA1 hash: 5b5a92c29290577a1012c7313eb5d0874d815672
MD5 hash: 7b7b46fdf3a0983934a68c3a0e3aa975
humanhash: social-avocado-yellow-early
File name:Codes.zip
Download: download sample
Signature AgentTesla
File size:447'969 bytes
First seen:2020-10-17 12:07:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:2Qqrn+PlkCvF2qqPqOlmOVNgLx02uudtdIyiY+Eh:RPPicfCqBOVWXNI1U
TLSH 9C94238CF07C5DC96E5F322C9E67A3F5654E6FA9250499F0B400246D2372EFEB320A60
Reporter abuse_ch
Tags:AgentTesla Outlook zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: EUR01-HE1-obe.outbound.protection.outlook.com
Sending IP: 40.92.65.96
From: feno_ u201 <feno_u201@outlook.fr>
Subject: justificatif
Attachment: Codes.zip (contains "Codes.exe")

AgentTesla SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Strictor
Status:
Malicious
First seen:
2020-10-17 11:03:29 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c9ed65f3e8b2c3e76cbde4e0beb836eaa6b830aed07f1fcd9d3de089de350b1f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments