MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12656591955b77037759aebd4fc90dfe9ac935fdc547f659148d70a64717adea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 12656591955b77037759aebd4fc90dfe9ac935fdc547f659148d70a64717adea
SHA3-384 hash: f99b3023f13f03d08177ccf6f881c53479ea8506cdb8aadd4b7a6eff5867be4e49632344518c908ea25e5c5af74ab8b8
SHA1 hash: 5a378696a32cda5b180dd05938811196c93d01c9
MD5 hash: 70e31d9f1c64b10c07389590fee04ddd
humanhash: echo-fix-queen-hamper
File name:Lee-Payment of AC.rar
Download: download sample
Signature AgentTesla
File size:376'885 bytes
First seen:2020-06-11 11:17:21 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:hMH6S8rz7R5QrMwSPN7FJmFik2B+kFPR88w5XnjX5FJSikoIge7U9EjeEiftDFvI:hBSOz7kDyNP+j2BrFi7Xnj3JSiOge7tB
TLSH FF8423510EF19E1F59F4D5F66A4F608F1C28BC984D1EA658D30280A9FAF46CD1FBDA20
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.exicoserver.com
Sending IP: 51.254.66.252
From: salwa@exicogroup.com
Subject: Bank Details
Attachment: Lee-Payment of AC.rar (contains "Lee-Payment of AC.exe")

AgentTesla SMTP exfil server:
smtp.moorefundz.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-11 11:19:05 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 12656591955b77037759aebd4fc90dfe9ac935fdc547f659148d70a64717adea

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments