MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07e10780b86a88f9882439c29afdb738543a0dde104ee0347c85067274bb816b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 07e10780b86a88f9882439c29afdb738543a0dde104ee0347c85067274bb816b
SHA3-384 hash: 412c9cfbca59bd5350809ae7211e9c1bd2d293301385ec839635fc504f11c3a8bb2b1082730cac0461de8cda9ed62d40
SHA1 hash: b07e3e7934995717c4813adfab424d56d988c7c9
MD5 hash: ee50f84c807a492940ae3a63b6c30480
humanhash: seven-salami-earth-oscar
File name:PAYMENT INSTRUCTIONS COPY.r15
Download: download sample
Signature AgentTesla
File size:278'556 bytes
First seen:2020-04-29 19:14:21 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:75XMlMjzTN+h4e4doiNWShvZzurOgSmHqGXvYTdTxz4cDxthPF01rQ:9clMjzTwW3OiNWSHCKtmHdgZTRPVF+Q
TLSH 924423BFF801030B7500E2982A6E8254E1FFDB7385599A8CF289DFB10749D941756F9E
Reporter abuse_ch
Tags:AgentTesla r15


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dhavalgroup.net
Sending IP: 103.99.2.4
From: account1@dhavalgroup.net
Subject: RE: PAYMENT INSTRUCTIONS
Attachment: PAYMENT INSTRUCTIONS COPY.r15 (contains "PAYMENT INSTRUCTIONS COPY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-29 10:10:00 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 07e10780b86a88f9882439c29afdb738543a0dde104ee0347c85067274bb816b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments