MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bd02d0ceff4d55d3af4e647edcea8952b9ae5eacc63efa2d7c140846d1388f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0bd02d0ceff4d55d3af4e647edcea8952b9ae5eacc63efa2d7c140846d1388f4
SHA3-384 hash: 06997f2f0e9a7900963cbf5f5ee4a0b5b34795664e54e67933c345949f38f13aecfc67364ac9723424678105eda58884
SHA1 hash: b6326a68c73990fb9965539611e99e5d90d392dd
MD5 hash: 325ce12cdd1a4986c8cadfd215053293
humanhash: jersey-kilo-helium-spaghetti
File name:Reconfirm.pdf.z
Download: download sample
Signature AgentTesla
File size:588'551 bytes
First seen:2020-06-03 17:27:31 UTC
Last seen:2020-06-04 05:50:59 UTC
File type: z
MIME type:application/x-rar
ssdeep 12288:Rv5y91eT5rJYlSpw+SCFEkpzMsG5BuNnPPCi6Qixow:e91GrJYoTzFQbYPPRiKw
TLSH 81C4230019CD58C2A7D48F0FD33E314D71AC0CBB0CAE1A9838657D666FB6392796799B
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: alkuhaimi.com
Sending IP: 37.48.85.217
From: Purchase manager<RAJAH@alkuhaimi.com>
Reply-To: Purchase@alkuhaimi.com
Subject: Please Reconfirm,
Attachment: Reconfirm.pdf.z (contains "Reconfirm.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 17:35:55 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 0bd02d0ceff4d55d3af4e647edcea8952b9ae5eacc63efa2d7c140846d1388f4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments