MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 083a3c3446b4c7465f489a58e7583b10177964e61e509239f3ba149da4818c2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 083a3c3446b4c7465f489a58e7583b10177964e61e509239f3ba149da4818c2a
SHA3-384 hash: b20ef4491088fae0cf5e7e500b19047e648f80459a8ee4726deca170ed078c43f2e3fd43447f23cb7beb420eca59c84d
SHA1 hash: 33aa8ddc4ffde8e5cfe79cba8b92e636574800f2
MD5 hash: a2da071d2d9a8f8e12aaa23287b21dc5
humanhash: floor-failed-arkansas-fifteen
File name:INV-CSPL418819-20 RS.2360.rar
Download: download sample
Signature AgentTesla
File size:449'457 bytes
First seen:2020-08-19 11:22:02 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:NstnLE6t9Uj29BDpmGY8OHPlXV/SniFvFufVINwc5i:QJrUjID4G4Ph4iFvEIR5i
TLSH 1BA42380DC90DB535E9A56866C8D6E4E2E881EA7C47CCD482FB74C05AF0FB9FE478494
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 81.171.9.143
From: Ms. Ishardas <chomi0605@panpacific.co.kr>
Reply-To: Ms. Ishardas <surnit9041@gmail.com>
Subject: Re: invoice no CSPL/4188/19-20 RS.2360 Payment Detail
Attachment: INV-CSPL418819-20 RS.2360.rar (contains "INV-CSPL418819-20 RS.2360.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-19 11:23:09 UTC
AV detection:
18 of 47 (38.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 083a3c3446b4c7465f489a58e7583b10177964e61e509239f3ba149da4818c2a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments