MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d00e4d69df95cac48237d525830611263642277a68a1415a12ee4fd613076556. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d00e4d69df95cac48237d525830611263642277a68a1415a12ee4fd613076556
SHA3-384 hash: 2d9bf061fdb3e161c267c137dc3e2f84d2886ef8067cddeeeaa211f7486edf08fb2bb3721d46e66f479f46fcf5a50752
SHA1 hash: 60716168e90d71f6b0af02facfd9fb49dc2fdb28
MD5 hash: 0bde4fd2519890815ca13c3b9cfe4582
humanhash: sad-winter-xray-fanta
File name:Purchase Order AA000345429062020.PDF.zip
Download: download sample
Signature AgentTesla
File size:397'769 bytes
First seen:2020-06-29 07:50:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:1rG7jCR2zwcmuvlCdgEkgtFqjyXTFwBGaX05:ROjzwcXNugEPtFq0Tf405
TLSH 2A84232ACF58BF7997D4526009D7494A36F2E7FC39428A0D569CCB6C20BE990F362258
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: talk.corporates-servers.net
Sending IP: 66.45.255.236
From: Manuela Genovese <georgebrown00123@severmsg.com>
Reply-To: astuccioguida@libero.it
Subject: Ri: Acquisto_Ordine#AA0234029062020
Attachment: Purchase Order AA000345429062020.PDF.zip (contains "Purchase Order AA0003454#29062020.PDF.exe")

AgentTesla SMTP exfil server:
mail.pakistanconsulateny.org:587

AgentTesla SMTP exfil email address:
security@pakistanconsulateny.org

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-29 07:52:06 UTC
AV detection:
19 of 47 (40.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d00e4d69df95cac48237d525830611263642277a68a1415a12ee4fd613076556

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments