MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d2a89a5326f71889dd6c91e83af17f5ad3b8f03f76713df67b438c5622b3d9e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d2a89a5326f71889dd6c91e83af17f5ad3b8f03f76713df67b438c5622b3d9e6
SHA3-384 hash: 4351e032a3039b709b67d0967116c05f868805d2f525a36c62eb3d8c0efc17e4d6893299802189c9aca4be29d2cb67f8
SHA1 hash: 8d6680a167e5143fec883f748192bf774f618e58
MD5 hash: 0f22ba5802bdde2de3fe873fa7d180bb
humanhash: whiskey-chicken-item-four
File name:List of documents.rar
Download: download sample
Signature AgentTesla
File size:399'132 bytes
First seen:2020-06-17 05:40:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:HyBX2xlSsimmHwbMxFBMuLdieW8T383+HI:HyEDSdHFBZLdieW8De
TLSH BF84236E07C5DECAF536E2C497D181271DF33744B91EB7C72292850ADCA2894EFB1298
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: qproxy2.mail.unifiedlayer.com
Sending IP: 69.89.16.161
From: Silva David <anuradhad@medtekindia.net>
Subject: Please let us know what you think about the new corrected documents
Attachment: List of documents.rar (contains "List of documents.exe")

AgentTesla SMTP exfil server:
smtp.1and1.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-17 05:42:04 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d2a89a5326f71889dd6c91e83af17f5ad3b8f03f76713df67b438c5622b3d9e6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments