MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e2201021c4ba691a84a29fa383df4a16e76317b1ef2b51271c9cd669276ec754. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 2
| SHA256 hash: | e2201021c4ba691a84a29fa383df4a16e76317b1ef2b51271c9cd669276ec754 |
|---|---|
| SHA3-384 hash: | 9671c2aeeeb05a07e137525dffe4a83d976c3427f30f7abcec3264bcfa78708df4cc621539ebd8fd327c4c8b5103530e |
| SHA1 hash: | ffd7385efa90bbea791a3f566a375a02f6ed72e5 |
| MD5 hash: | 5786d59df9edbf8ed9a0699709bc6bd6 |
| humanhash: | zebra-bravo-mockingbird-uncle |
| File name: | ORDER REQUIRED DETAILS 2020.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 456'263 bytes |
| First seen: | 2020-12-03 08:47:44 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:hBQ3ev25Nf05x8NffA0LxCIlb2EWzdC6/:nq35e5xGLgzg6/ |
| TLSH | A8A4234329EC79B2CBD22C4F0584C66B9F774CCB11B421145392D6CA7CC5EB296DF89A |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: plasticseurope.org
Sending IP: 103.114.107.112
From: info@plasticseurope.org
Subject: Required Delivery And Shipment Order
Attachment: ORDER REQUIRED DETAILS 2020.rar (contains "ORDER REQUIRED DETAILS 2020.exe")
AgentTesla SMTP exfil server:
mail.mutasmutfak.com.tr:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.