MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf8a97a6c62e39786d77a4b77b9257aa2e3cdffcb29e313e3a550fd9075d9852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cf8a97a6c62e39786d77a4b77b9257aa2e3cdffcb29e313e3a550fd9075d9852
SHA3-384 hash: 05642a8d0aa2b51abf71db2efebee24455e47cb52ebf4a60db9c025214b743e228b9a68d0b681d07b1f6f13746bd34b7
SHA1 hash: 01f9bdf837e9d8d75a9e159c9ad79b7e8458f63e
MD5 hash: 22c805f78af90e437082d47d3c54984a
humanhash: texas-butter-batman-cold
File name:PO1276579.pdf.7z
Download: download sample
Signature AgentTesla
File size:583'276 bytes
First seen:2020-08-31 11:32:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Yauda7F5V6WmAolAxxtZPKVqO+vh+leAlp3Up:YJQ5mAoytZbObLUp
TLSH 88C433F98B94B29EFD10508DB82631769D97D3C2AEF79690F7182039870D3EBF488059
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.filrep.com
Sending IP: 66.23.225.124
From: Suresh Kulchandani<Suresh_Kulchandani@mail.bg>
Reply-To: Suresh Kulchandani<Suresh_Kulchandani@mail.bg>
Subject: New order for cables
Attachment: PO1276579.pdf.7z (contains "PO1276579.pdf.exe")

AgentTesla SMTP exfil server:
server126.web-hosting.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-31 03:54:58 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip cf8a97a6c62e39786d77a4b77b9257aa2e3cdffcb29e313e3a550fd9075d9852

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments