MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe1968b73e441e7febc1bef7a3cacaef7c5ca01536dc25c53a093cb716ad6c00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: fe1968b73e441e7febc1bef7a3cacaef7c5ca01536dc25c53a093cb716ad6c00
SHA3-384 hash: b737ad237bf2b6a1b82267bb927aeb2c73bcfade68c7d74b25ead45214d1dd98eb2f6a93ae644c8d3413d0d83b142988
SHA1 hash: d218ffe742362a562019a76bffbf6845fcdef35d
MD5 hash: cc914757ce965bbcb01cc63a170d8c0b
humanhash: cat-dakota-november-kansas
File name:Price list.zip
Download: download sample
Signature AgentTesla
File size:343'116 bytes
First seen:2020-05-27 06:39:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:FEfNuauKZDJNDtMPURdCvZB4Y+x8CsRP84DKrAik059DI7GPEw8fyv+ZeILP:F8uauKZf6PpRB04DKrvC7GPEw8VeILP
TLSH 0E742320DD9A11E21292CBAE71B910EF1B3F5B427459DC803720D342D4BBFD7992D8DA
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: uppercrustjakarta.com
Sending IP: 37.49.230.164
From: Mary Wiley <mary.a.wiley@uppercrustjakarta.com>
Reply-To: yingzhang67@yahoo.com
Subject: Revision of Quotation
Attachment: Price list.zip (contains "Price list.exe")

AgentTesla SMTP exfil server:
smtp.serviceconsutant.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Mbt
Status:
Malicious
First seen:
2020-05-27 01:44:40 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip fe1968b73e441e7febc1bef7a3cacaef7c5ca01536dc25c53a093cb716ad6c00

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments