MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a7d67477402c844493e9cfe07ee8f231cec6c374c8ff97c2033fb0791d1fc3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2a7d67477402c844493e9cfe07ee8f231cec6c374c8ff97c2033fb0791d1fc3e
SHA3-384 hash: 2f4389ed3c8bf48ce61b2e74a51976d8342eea2bead3e365d684c5e33027998b183d4019554247708e5e11a9d7e0b8b7
SHA1 hash: 489e0f5241c6bb90d27364e5263d6779f08e2255
MD5 hash: 7ea854dc96909dee467dd532f01f33e6
humanhash: mississippi-friend-victor-july
File name:Bản sao hóa đơn 000201106012020.7z
Download: download sample
Signature AgentTesla
File size:479'983 bytes
First seen:2020-06-02 08:15:08 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:ucjBRM9hJO3yIXOK5Xk/78rD8cRvZPmrsvUCcgCc8MSR5:962neKBk/gDRRvZBUS8MSf
TLSH F3A42369A5B5FDEB55C00B7F52F5312120F218A02EC7980CC9A6D7CDEC3AD22B7C9991
Reporter abuse_ch
Tags:7z AgentTesla geo VNM


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.processing.ro
Sending IP: 86.107.224.178
From: Truong Doung <truongdoung20@gmail.com>
Subject: Bản sao hóa đơn
Attachment: Bản sao hóa đơn 000201106012020.7z (contains "Bản sao hóa đơn 000201106012020.exe")

AgentTesla SMTP exfil server:
mail.ductoslimpios.com.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-02 08:36:27 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 2a7d67477402c844493e9cfe07ee8f231cec6c374c8ff97c2033fb0791d1fc3e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments