MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ca185bbde5f850121379922f5150a203bcf3c05720be29aed5a4af4cbd881c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1ca185bbde5f850121379922f5150a203bcf3c05720be29aed5a4af4cbd881c3
SHA3-384 hash: f239e38877253fddf0f4eb62f92a52df7a046e26f421ad1d06d536ccaa303b0f51e9e63edcb4d94dde9866ea888bad79
SHA1 hash: b2415d31d39095f333cc5921672c01e64d8eb77d
MD5 hash: a1a8549543124ef4191cdab46aa99386
humanhash: massachusetts-island-social-hamper
File name:INVOICE~DOC.zip
Download: download sample
Signature AgentTesla
File size:360'610 bytes
First seen:2020-06-26 06:12:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:IscaB6G5/6l9daBZ5d21E7uEWCb+iDmVAqjRAuHoCCva5K3wYIVP9bnPQ6rWzpKF:IAF5CPdaRru4DmWqjRAuIpk5P9nTWzpc
TLSH FB7423041D28F4C1E54E8B334D658BBA74F136AAA1C213F24ECB041FDFD295B85D6EA9
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: igitgroup.org
Sending IP: 103.151.122.121
From: infouae@igitgroup.org
Attachment: INVOICE~DOC.zip (contains "INVOICE~DOC.exe")

AgentTesla SMTP exfil server:
smtp.ionos.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 06:14:05 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 1ca185bbde5f850121379922f5150a203bcf3c05720be29aed5a4af4cbd881c3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments