MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e837bf205634eceda09b8b78f49d41fbd7a9d881801bceef361181da3bc65092. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e837bf205634eceda09b8b78f49d41fbd7a9d881801bceef361181da3bc65092
SHA3-384 hash: 75947fc5f7d516aadba0822e12e021566d7f71a749bd200d4f7b9b3d8cf923b59d3a270f7b9b6f4ce9d90542bb74aada
SHA1 hash: ce08326798824cb855c740dd74f9bf5af45d8b89
MD5 hash: b23a67e178422f25d6c599daf0cb0c50
humanhash: cat-bulldog-nitrogen-fifteen
File name:Invoice.xls.pdf
Download: download sample
Signature AgentTesla
File size:449'317 bytes
First seen:2020-07-11 16:40:43 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:xWN/HsgmA+7dxBKgPHvvpSj5mRhIyMIRJKJJBS:YZHDYdBPXWgWyMe
TLSH 91A423A5908A5EDBCA9CBB40C34C41D2A371B91BBEAD1F3A4CDED644F7C1715C663882
Reporter abuse_ch
Tags:AgentTesla pdf


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: atomicka.localdomain
Sending IP: 202.52.134.122
From: Sharon So <gopi@alangroups.com>
Subject: Confirm Invoices For Payment Purpose
Attachment: Invoice.xls.pdf (contains "Invoice.xls.exe")

AgentTesla SMTP exfil server:
smtp.rezuit.pro:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-11 16:42:05 UTC
AV detection:
12 of 47 (25.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar e837bf205634eceda09b8b78f49d41fbd7a9d881801bceef361181da3bc65092

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments