MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e3733f87c71526c3f654a3fe28fd350069047fb86a7ad5ec3d51b2b8ab7d280. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e3733f87c71526c3f654a3fe28fd350069047fb86a7ad5ec3d51b2b8ab7d280
SHA3-384 hash: c5328bf38365a9601db55cc807c2a4f52b093cf885c664fea089f8aea65fc13e8d7b23b2dbe741931b223a3fef69a78f
SHA1 hash: 1f92330739c0e09485fbd7287bdc08e88fe61ecf
MD5 hash: 4d2679a3aeedde432194ef9571d8bf77
humanhash: september-september-wisconsin-floor
File name:RFQ AKBAR050520.zip
Download: download sample
Signature AgentTesla
File size:300'595 bytes
First seen:2020-05-05 07:12:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:m0cD06ODD/oNMbuMJRIN7Qs9KVPN+BgC6nEi0y4wqOToU1BK5:m02XO7PRJRIhQKRiRPqOToU/E
TLSH B354232E542A2FDEA1F8E4364C7F405AF52E658E158DB100AD20CA5E260951DFF93CFE
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: lorencia.com
Sending IP: 94.177.243.120
From: Gibu Reba <reba@walsh.com>
Subject: AKBAR/PO/0505/20/TOP URGENT
Attachment: RFQ AKBAR050520.zip (contains "RFQ AKBAR050520.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-05 07:35:43 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0e3733f87c71526c3f654a3fe28fd350069047fb86a7ad5ec3d51b2b8ab7d280

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments