MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5d039713bf1fc7ec618e22f918a762f9b0637dea7aa8802fc681866a245b4a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d5d039713bf1fc7ec618e22f918a762f9b0637dea7aa8802fc681866a245b4a1
SHA3-384 hash: 67cfa0f943e3375fe2e459c0d62edbcbaac7aea0e97c135d21e1ced500f0f03eb25c65966874a84207aed5d96bb6f58a
SHA1 hash: af94aa7561e33c0b0cb367926649e89fa631a6a1
MD5 hash: 0b41666dd4cbf761f388ba01b0c11543
humanhash: angel-fruit-whiskey-blue
File name:P01307020.rar
Download: download sample
Signature AgentTesla
File size:656'454 bytes
First seen:2020-07-13 06:23:59 UTC
Last seen:2020-07-13 06:25:12 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:P8F07tZ3hc+UpA/6N2+IJ+RfJRn6I0PPGUvjh+SXWyaGtZNtYsf:BhjU2+IJWP6I2vjAmWqvvf
TLSH 29D42339B2D9E2021ED8DF88CC836782DF1F825CC66464AE395B7A78791D31683C51F1
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: virtualhost.com.tw
Sending IP: 175.183.3.134
From: PT. Gamako Ekakarsa <sales@gamako.co.id>
Reply-To: jr210131mr@gmail.com
Subject: NEW ORDER
Attachment: P01307020.rar (contains "P0#1307020.bat")

AgentTesla SMTP exfil server:
mail.sonorainmuebles.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-13 06:25:08 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d5d039713bf1fc7ec618e22f918a762f9b0637dea7aa8802fc681866a245b4a1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments