MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07a196e045c62e5f55a13093caf3fa5f4e4b4c59018903b1af53205f6c836631. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 07a196e045c62e5f55a13093caf3fa5f4e4b4c59018903b1af53205f6c836631
SHA3-384 hash: 6b3bd053dcbd8c7ea90e7e95b8d539c792fbcd3c2d38a66ceec7890aed0ce11f37e5929e3a84661853ba27aedb4d3abf
SHA1 hash: d48dbee95e3a23d66a139fb3e569603f9c96f16c
MD5 hash: 4999bea792c74ef3fde9b4a71293d067
humanhash: carpet-snake-colorado-eight
File name:Quotation SSQT200630.zip
Download: download sample
Signature AgentTesla
File size:397'674 bytes
First seen:2020-06-29 12:36:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:6NlLhyr8q4x6oImFraEhnV4nIkJMsfy/gSDBu8:6Nure60xLhnV4njMsfOg4Bz
TLSH F2842341188EB98B085766B8B76273A17C50FD3E62BEE311444BB64C6FED99B1350CF2
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vega.awedns.com
Sending IP: 101.99.77.52
From: Michael Lim <enquiry@emasling.com.my>
Reply-To: liangchiphlippines@gmail.com
Subject: Quotation SSQT200630, dated 29/06/2020
Attachment: Quotation SSQT200630.zip (contains "Quotation SSQT200630.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-29 12:38:12 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 07a196e045c62e5f55a13093caf3fa5f4e4b4c59018903b1af53205f6c836631

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments