MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8e78e9e5f6cef4d8d68f6aa53923c1d899bd7ad0f1094c2257e68c595a91bfe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e8e78e9e5f6cef4d8d68f6aa53923c1d899bd7ad0f1094c2257e68c595a91bfe
SHA3-384 hash: e71150fa64579b228301bf314118d3928c74e2461e18953d99d719013003d160cf2adc2f15e283cd97294c351fb4188c
SHA1 hash: 77b870496107edb916f78e83538a932047a044a9
MD5 hash: 2b01988b09db04abdbd45ef82f4eef6a
humanhash: missouri-happy-carolina-dakota
File name:P.O.zip
Download: download sample
Signature AgentTesla
File size:245'720 bytes
First seen:2020-07-07 17:17:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:S172SA0tN6+HCmLk5BeO5aUWYdWxxGscYObk0WmbAyoR3gE:Sh2SA0DH9mBeOklLx05bZWmbAyoCE
TLSH C23423F1864EC828FE95B77E061836397DE8A9B4DE4FE60A432C5E98110D38FF42D645
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.benektekstil.com
Sending IP: 88.249.210.205
From: JEONG WOO-CHOIPOSCO <info@energytech.co.kr>
Subject: PURCHASE ORDER
Attachment: P.O.zip (contains "chusmoni.exe")

AgentTesla SMTP exfil server:
mail.lallyautomobiles.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-07 17:19:04 UTC
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e8e78e9e5f6cef4d8d68f6aa53923c1d899bd7ad0f1094c2257e68c595a91bfe

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments