MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03ab26e4e7b6c0c994ace32407bd4b5049db52ac298a389e06ea88d0583d2de7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 03ab26e4e7b6c0c994ace32407bd4b5049db52ac298a389e06ea88d0583d2de7
SHA3-384 hash: 5a665f9218cafad98b9c9a8b05deef310c8e005e9745ba55bf6f83326bfb1f0845aa92593a6c3816143fc25999a276aa
SHA1 hash: d3eea6b59e4cc01a5ccc2075184cf23dcab89189
MD5 hash: 6421b586c3c4677b57be85891ff79205
humanhash: delta-hot-jersey-bulldog
File name:INV_20200829154846.rar
Download: download sample
Signature AgentTesla
File size:503'861 bytes
First seen:2020-08-31 11:27:44 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:KfrHsXEbdbJNwG2uOWaLbR/ju3FnezMxe0X1tXHd6:4FJNV2PJL9CoK1tX96
TLSH A7B42302266AE9F4499FCC0A64E69AFDF0375D841336DD63463715E2E437A3A20A7DCC
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.servidorinternet.net
Sending IP: 89.26.247.117
From: Faisal Gulzar <info@ipluae.com>
Subject: Invoice for payment
Attachment: INV_20200829154846.rar (contains "INV_20200829154846.exe")

AgentTesla SMTP exfil server:
mail.gascuenca.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-31 04:53:41 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 03ab26e4e7b6c0c994ace32407bd4b5049db52ac298a389e06ea88d0583d2de7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments