MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d96bccad8e8f82c83c0628bcb5eb7a1045137973e46f10950bd42350640efea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0d96bccad8e8f82c83c0628bcb5eb7a1045137973e46f10950bd42350640efea
SHA3-384 hash: 5073c9da45f560130db5cfb28f694757431b01c772d37a0f2deac84e26b2a8e23b4cbfffffe6ea5fa9000e13d5f815de
SHA1 hash: e70e379aed973231782e050e72e1763489e17372
MD5 hash: 1faa477fc3f60fcc3f68f7a9e493e631
humanhash: arkansas-cold-lake-tango
File name:PaymentConfirmation.CAB
Download: download sample
Signature AgentTesla
File size:263'031 bytes
First seen:2020-06-08 07:46:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:0HQiAa5UDaS1en9KXUCroSGGB1RP4wNy3g17+y7ec/AfRrAC+x:MQx1e9GUkrVywN6g1L7nC+x
TLSH 6144235A0D339E704D0B9DD6C68B15CD8EB9183D30FF6748964BDEC5029EEA43EA8069
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ards.co.za
Sending IP: 190.117.101.190
From: Chrystal Van Wyk <chrystal@ards.co.za>
Reply-To: Chrystal Van Wyk <aahvanrooyen@gmail.com>
Subject: Fwd: Payment confirmation
Attachment: PaymentConfirmation.CAB (contains "PaymentConfirmation.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-08 07:48:04 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0d96bccad8e8f82c83c0628bcb5eb7a1045137973e46f10950bd42350640efea

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments