MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20d71bfff3c6f4109aab41922c346c6d05179a8fbefff9d130b6ceda25a8bbdf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 20d71bfff3c6f4109aab41922c346c6d05179a8fbefff9d130b6ceda25a8bbdf
SHA3-384 hash: 0c6401bbed4451cd77b170c1b28ea4841f66151023a89180379f5319748e3914d643fe99ec39286dc62acdd9582f6bb9
SHA1 hash: 1159cdbd9e257abc7a53040f1ce03906ac04746b
MD5 hash: bbf99660f551314848b0c42ca8c4c014
humanhash: seven-xray-jupiter-lithium
File name:TT copy.zip
Download: download sample
Signature AgentTesla
File size:428'060 bytes
First seen:2020-05-12 14:35:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:F5khf/Zodz6INaEPx8RHv98V+irGLcZRjB+e7ov0:FGXtIoEP1vZqhs
TLSH F894232ECB4EB470EBAA54532DD50AB37C6D573563CE880E400C9E1F83A6DD912E5E74
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fw6a.wadns.net
Sending IP: 41.185.81.144
From: Xiamen<sales15@163.com>
Reply-To: <emilianaitaly@gmail.com>
Subject: RE:Payment Copy from the bank for our last order
Attachment: TT copy.zip (contains "TT copy.exe")

AgentTesla SMTP exfil server:
mail.fakly-cambodia.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-12 14:02:31 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 20d71bfff3c6f4109aab41922c346c6d05179a8fbefff9d130b6ceda25a8bbdf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments