MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d490c86c10df82c40d531cd9beb6721910e114e4d34d38a51dbfa5663655be6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d490c86c10df82c40d531cd9beb6721910e114e4d34d38a51dbfa5663655be6a
SHA3-384 hash: f05e94ffbe8eea86c9c525201dd9f0e5d05b1973e0a9f8cded5361a46df041c9a0d5142df3f9f95e8f6c718ca58a4b1e
SHA1 hash: 5c120a9b11bfaeb81f87964cdebc3731b2e51bb6
MD5 hash: 17e1e2f49831208d4288fdf9ee8edd97
humanhash: jersey-wisconsin-alanine-summer
File name:adjunto_de_oferta_urgente.7z
Download: download sample
Signature AgentTesla
File size:385'553 bytes
First seen:2020-07-07 09:01:26 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 6144:C2mewFsD1JURC7XYLVO4QdEgVoqnO5khvqEJU2gI22zf8DNtQlMdgX24lHvj:pmRO+C76VNQd5ouOq827mptOvPj
TLSH 20842300AE157CECE49E282F9F757AD95DD04B4A55C9272AE9B8C2F3344C5F0884C9FA
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: master.dtnetwork.hu
Sending IP: 195.70.37.203
From: Sebastián <officeSebastian@posot.es>
Subject: Fw: oferta urgente
Attachment: adjunto_de_oferta_urgente.7z (contains "adjunto_de_oferta_urgente.exe")

AgentTesla FTP exfil server:
ftp.rologisped.com:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-07 09:03:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z d490c86c10df82c40d531cd9beb6721910e114e4d34d38a51dbfa5663655be6a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments