MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10555179020556fb461d05be6edca9e067de3c229ced8277b82db4c676299d9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 10555179020556fb461d05be6edca9e067de3c229ced8277b82db4c676299d9a
SHA3-384 hash: 6d94607e5953348a293992899906f201c5680f34b19a179409dd1576ba96a2074aa710a6c3375996ff0d9914d920dfab
SHA1 hash: 2b25609845f3bb86d4fa9c44fc54115d9c2844fa
MD5 hash: 00a7a00bec44fc6ccb1f22688c908000
humanhash: sink-bulldog-cat-salami
File name:payment against your invoi.zip
Download: download sample
Signature AgentTesla
File size:375'125 bytes
First seen:2020-07-16 06:51:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:pNCQ9tLMXFOdC2NvwHZPII5b4yehq3b1cNc+EWrBdrEQ6H24aJgeh+09VLH4WdjJ:pNNl+d2NgZwC0hqLIB9EzUh+09p4iffJ
TLSH D084236AA482131F494F4E7F8C04E13B4ADCE714AB8637D749DB9E4519B373A0CAF291
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.atlastravels.com
Sending IP: 195.201.131.113
From: Robin.thampi <robin.thampi@palmshotelmauritius.com>
Subject: 形式发票"MG_40300627_0090
Attachment: payment against your invoi.zip (contains "payment against your invoi.exe")

AgentTesla SMTP exfil server:
mail.trip24now.com:587

AgentTesla SMTP exfil email address:
services@trip24now.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-16 06:53:04 UTC
AV detection:
32 of 47 (68.09%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 10555179020556fb461d05be6edca9e067de3c229ced8277b82db4c676299d9a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments