MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 00a9be0f7187b170c10f477ca10303fbf6cc87667a3ad64eb3e73186869e819f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 00a9be0f7187b170c10f477ca10303fbf6cc87667a3ad64eb3e73186869e819f
SHA3-384 hash: 3e15e3f82ca07f80b0d81fc51b1617fed07710255b1e927defab5b98110b32c97bdac43a16f301dacda80686a95eb46a
SHA1 hash: 132e85c7b1aa6b155b6551830fc49f6dacc4a0f6
MD5 hash: ed5299ea9dc9cb791f0981a444d8d25a
humanhash: dakota-pip-alaska-uncle
File name:Order_0720PDF.7z
Download: download sample
Signature AgentTesla
File size:270'629 bytes
First seen:2020-07-07 08:38:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Wy/NcMrtGvdWqvlBUaHM1jOq5dDDR7UVvfE:WA7OdHias5ZnnR7iE
TLSH D344234F15F84986DF066E0142C7578EBCA10967EAB0C683B8B706C5F90558AFFA4EDC
Reporter abuse_ch
Tags:7z AgentTesla BGR geo


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gyp.gr
Sending IP: 46.227.62.27
From: Tapani Koskimies <tapani.koskimies@egavrielides.fi>
Reply-To: worldnetofficemailer@gmail.com
Subject: VS: Поръчка 0720 !!!
Attachment: Order_0720PDF.7z (contains "Order_0720PDF.exe")

AgentTesla FTP exfil server:
ftp.solarcenter.ro:21

AgentTesla FTP exfil user name:
webmaster@solarcenter.ro

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-07 08:40:06 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 00a9be0f7187b170c10f477ca10303fbf6cc87667a3ad64eb3e73186869e819f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments