MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e11b20eed8c822c17421c83e0e4c39ce59c8aab5d6c8f0887a9fed96b24bd67b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e11b20eed8c822c17421c83e0e4c39ce59c8aab5d6c8f0887a9fed96b24bd67b
SHA3-384 hash: 159d03ac562ad105ec7f7ceb5216d62ccb9b9276c315031d6efc35c30283cbd318a2a86fcf9f3f1ff6ab6c551252f2ab
SHA1 hash: 8af9259ee125ccc46c6a168496320a12eb58bf30
MD5 hash: 08e71f3e774574bc01e4c82c237dfb8b
humanhash: sink-black-uranus-skylark
File name:uzorak proizvoda.zip
Download: download sample
Signature AgentTesla
File size:1'083'578 bytes
First seen:2020-06-15 12:25:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:0vYHXrZVx2gD/JRF4rQhZx4opRp+sDKu4xkIExN91:+YHbbxFFz4rQhZxhDDD4QN91
TLSH 5E3533DA95248917ACD87D366DB2ACA08BD6A8C5D713532C588CE3CC2FCD698840FDE1
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fre.freespirittours.ge
Sending IP: 192.254.140.61
From: mn.vilanesic@mn.co.rs
Subject: spavanje za plaćanje
Attachment: uzorak proizvoda.zip (contains "uzorak proizvoda.exe")

AgentTesla SMTP exfil server:
mail.s461.sureserver.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Worm.Ramnit
Status:
Malicious
First seen:
2020-06-15 12:27:04 UTC
AV detection:
38 of 48 (79.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e11b20eed8c822c17421c83e0e4c39ce59c8aab5d6c8f0887a9fed96b24bd67b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments