MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f653a833dc5f9e90080a5b4386902ad181df70d752bc5b1cd0f75a8c6e77c464. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | f653a833dc5f9e90080a5b4386902ad181df70d752bc5b1cd0f75a8c6e77c464 |
|---|---|
| SHA3-384 hash: | a60284863c3f3075e7d56f969537c31ca91b0df6dbc35622f8b8c13ef466aa8fac6eb507f5413197b57f3b39f62fffc0 |
| SHA1 hash: | 2151708322a905f214187d68bec999d040cb3141 |
| MD5 hash: | 77ba828ba0d59b53fe34a4d1889bc62b |
| humanhash: | princess-winter-friend-fix |
| File name: | inquiry.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 868'639 bytes |
| First seen: | 2020-08-31 10:47:45 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 24576:4IcFQxhc6XEZ5D/qhdNHApbbsLxBMIfVZmpLu0GhscVfDDpaMo:4IcFQxhcnZ5DQHosLxmcVqyKcZ1o |
| TLSH | 75052351135098ACD08C36ABF3785F62B9818531538FBC21353C7DDAEE9D0B25AE9CAD |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: urbanhome.ae
Sending IP: 176.123.10.165
From: Kaleem <a.kaleem@urbanhome.ae>
Subject: URGENT INQUIRY
Attachment: inquiry.zip (contains "inquiry.exe")
AgentTesla SMTP exfil server:
smtp.millndustries.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.NanoBot
Status:
Malicious
First seen:
2020-08-31 04:09:59 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.