MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff36709436923f3de127a7e85d624c20b000435894f643a5d0f5c157a9bc1aac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ff36709436923f3de127a7e85d624c20b000435894f643a5d0f5c157a9bc1aac
SHA3-384 hash: 4b55db93513d29490eddf0b792b34c0261ac3ffada801d24515d7dda4df62ad66e873aa4f6370e0a7b90b97728ec78a9
SHA1 hash: 3b41815c361dd3c54498002a9bcdcc2dc5fe2f31
MD5 hash: 0a8c396e7ab77fadd84edf0b07652d47
humanhash: minnesota-ten-dakota-bacon
File name:Order 17034 PDF.zip
Download: download sample
Signature AgentTesla
File size:813'969 bytes
First seen:2020-10-06 05:40:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:vEREry7YLVkIHI8OUyHdwZWUl2G+FRBFlWaEI9Lnk:vBy7BdxURG3bJEIe
TLSH F6053384E13F56CA2ED48212A548A4AE4690DAEBF630AB1601CA3FD38F4D515C3B3C5E
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sitemastersupplies.co.uk
Sending IP: 172.93.165.152
From: Sitemaster Supplies Ltd <distributors@sitemastersupplies.co.uk>
Subject: Provisional Order Inquiry.
Attachment: Order 17034 PDF.zip (contains "Order 17034 PDF.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-05 23:51:18 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip ff36709436923f3de127a7e85d624c20b000435894f643a5d0f5c157a9bc1aac

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments