MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d94892b89e55182f821519e2a1e3ddd422c1260ab4ee09fcfb7c1f37ed0db36e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d94892b89e55182f821519e2a1e3ddd422c1260ab4ee09fcfb7c1f37ed0db36e
SHA3-384 hash: 733ea3070f8edc2314ba4fa6f44e39dc3cedd3d96bf84cad15247fc5c02a13ba195233173786a59018dc108114c668c0
SHA1 hash: b63e4b2fa4b2c14e4d0c84055e4f367d690d7339
MD5 hash: 19237e11984642ef4f3718868ff71880
humanhash: five-coffee-hydrogen-montana
File name:Universal280720.Z
Download: download sample
Signature AgentTesla
File size:456'379 bytes
First seen:2020-07-29 10:55:02 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:UWKVLKI2iB90H8oSP74sgvrgGF/UjVMvA7wy+:VOLKI2+PUZvrg6cjlcb
TLSH 62A4231F6DA585243661F3EE07C6EDD80FE3EB14B6A11ABFA577C203D86321E2905253
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: abaad.om
Sending IP: 37.49.230.200
From: Syamkumar Korat <syam.kumar@abaad.om>
Subject: Bank Transfer Advice
Attachment: Universal280720.Z (contains "Universal280720.exe")

AgentTesla SMTP exfil server:
mail.transfastc.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-28 23:21:33 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z d94892b89e55182f821519e2a1e3ddd422c1260ab4ee09fcfb7c1f37ed0db36e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments