MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 017d16e2344d043a6034f393323ee454208824dd164bdd85a0010add7b8b1ffa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 017d16e2344d043a6034f393323ee454208824dd164bdd85a0010add7b8b1ffa
SHA3-384 hash: 2e6266eb0f677339fe6d04c4a8e396c5532d0407f8258dc2adec36ea9c639f54771959c8c63c043cb2b37e89caa93726
SHA1 hash: 2a9020f8aa668816d4c1346bd306298fcddde42e
MD5 hash: 128d63379fe1638f33d760ffde42245f
humanhash: south-mexico-glucose-india
File name:Quotation.gz
Download: download sample
Signature AgentTesla
File size:488'430 bytes
First seen:2020-07-29 05:11:53 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:WCC9i2AuM5vmx2db4UMAX3YH3y5oGBtifufpBj+yJiTVP0r:WMRe+LX3i3y5oTuyyJiTV8r
TLSH DFA4235531DCF1D5650D27F2432A46ADAB8ED322EB4676538C9F2C9E030DED38AD4E82
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.sap-express.com
Sending IP: 103.31.132.106
From: Sales <ashish.desai@heatgen.in>
Subject: **Quotations for RFQ RECEIVED**
Attachment: Quotation.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 05:13:06 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 017d16e2344d043a6034f393323ee454208824dd164bdd85a0010add7b8b1ffa

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments