MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 017d16e2344d043a6034f393323ee454208824dd164bdd85a0010add7b8b1ffa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 017d16e2344d043a6034f393323ee454208824dd164bdd85a0010add7b8b1ffa |
|---|---|
| SHA3-384 hash: | 2e6266eb0f677339fe6d04c4a8e396c5532d0407f8258dc2adec36ea9c639f54771959c8c63c043cb2b37e89caa93726 |
| SHA1 hash: | 2a9020f8aa668816d4c1346bd306298fcddde42e |
| MD5 hash: | 128d63379fe1638f33d760ffde42245f |
| humanhash: | south-mexico-glucose-india |
| File name: | Quotation.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 488'430 bytes |
| First seen: | 2020-07-29 05:11:53 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:WCC9i2AuM5vmx2db4UMAX3YH3y5oGBtifufpBj+yJiTVP0r:WMRe+LX3i3y5oTuyyJiTV8r |
| TLSH | DFA4235531DCF1D5650D27F2432A46ADAB8ED322EB4676538C9F2C9E030DED38AD4E82 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.sap-express.com
Sending IP: 103.31.132.106
From: Sales <ashish.desai@heatgen.in>
Subject: **Quotations for RFQ RECEIVED**
Attachment: Quotation.gz (contains "gunzipped")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 05:13:06 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Eldorado
Score:
0.90
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.