MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e9a799f28633c5eb42f049c991471a6f516f28ea3763db4be1afa3d1e9cada03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e9a799f28633c5eb42f049c991471a6f516f28ea3763db4be1afa3d1e9cada03
SHA3-384 hash: 64c5940c8dace2f4395ab660f12c3b2b70405a46356091454252e20f1fc3388e8df02a935348ad95266aeaf96d9a6328
SHA1 hash: 8c70ae7a1c13813e257d1f92614a203dc702327b
MD5 hash: ed27fb9cb72aa0ba59358a9300b18152
humanhash: sad-monkey-east-single
File name:MSDS - PVC K70 black.pdf.7z
Download: download sample
Signature AgentTesla
File size:404'134 bytes
First seen:2020-08-05 07:56:05 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:rsNIILRnAae+REXZPBVfhweX5TU32gdC5eAcpKO:rstLRnAaeQEXZPBV5wRrRf
TLSH 498423B60C883053AD62EC3BEBC9954943F8A87CBBC42DA3A5D5FA44361BC95365670C
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gyp.gr
Sending IP: 46.227.62.27
From: GLOBAL ATG P.C. <yupaporn.manattaisong@imcopack.com>
Subject: Fw: Offer for PE FR & PVC compound for cables production 05.08.2020
Attachment: MSDS - PVC K70 black.pdf.7z (contains "MSDS - PVC K70 black.pdf.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-05 07:57:06 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z e9a799f28633c5eb42f049c991471a6f516f28ea3763db4be1afa3d1e9cada03

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments