MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d51479cf5243058d209c77c0ddf005bcf86e946b50d9b9cd34405b475d75d47d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d51479cf5243058d209c77c0ddf005bcf86e946b50d9b9cd34405b475d75d47d
SHA3-384 hash: 955d0ebb160af021e42b74b42949da2607d162d4d6d5191d1e7f355ee8ea52e10f72624ab1815036094cb9bdfb805f5f
SHA1 hash: bee467c8c1f64cd6775f3caa1050060f655c41e0
MD5 hash: c866163c6840422d69fc68417646bf51
humanhash: video-november-mountain-utah
File name:Payment Advice Note from 19.11.cab
Download: download sample
Signature AgentTesla
File size:688'082 bytes
First seen:2020-11-20 07:49:11 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:GXYT7/OPTD2avYFoFLxKH4a8grP9jbXRiXzMwExlkkDHDxrleFM981hAOi1bu+:AYHWPfZFLYHG+P9jbXRQzMFx1DHhkW9z
TLSH 91E423D97901B64EC862513F5FB8CA64FA8A68F770FE56FF62421C2B491A10C400DD2F
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 45.137.22.56
From: noreply@upm.com
Subject: Payment Advice Note from 19.11.2020
Attachment: Payment Advice Note from 19.11.cab (contains "Payment Advice Note from 19.11.2020.exe")

AgentTesla SMTP exfil server:
mail.impresstilecleaners.com.au

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-19 23:00:04 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab d51479cf5243058d209c77c0ddf005bcf86e946b50d9b9cd34405b475d75d47d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments