MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb1b78489380fbca7547382be83729f656a4b36ee8e51e6d37c2aa49e81dd685. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: eb1b78489380fbca7547382be83729f656a4b36ee8e51e6d37c2aa49e81dd685
SHA3-384 hash: 01f0d0ce62a3980f081ebd914b9e4a33a4cf40b2783a28d955dcb56592a8fcebe3fb73f803d4fa3b4a20714f218da8b0
SHA1 hash: ac5afcf3c9d4a2558b74702a9724f929f6d0244b
MD5 hash: 6cc50fdd178e777cdd6848aa6c4f4250
humanhash: twelve-carolina-fruit-pizza
File name:Shipping Docs.zip
Download: download sample
Signature AgentTesla
File size:481'797 bytes
First seen:2020-06-02 10:31:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Aq4PqYWoA6eNTKCzrcZSgtMG9WZ3oQyqVOluHOuJM:ALC0AhNe7sZ3oaVOTuJM
TLSH 77A4232DEDA111FE011E4F73204E3B9349F521733ABB9564CB7B3B1AAF275A8908449D
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: redafire.com
Sending IP: 78.129.132.85
From: SEMAX DOCS <Hussam.AlZaaim@redafire.com>
Subject: Shipping Docs
Attachment: Shipping Docs.zip (contains "Shipping Docs.bat")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 09:24:22 UTC
AV detection:
7 of 47 (14.89%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip eb1b78489380fbca7547382be83729f656a4b36ee8e51e6d37c2aa49e81dd685

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments