MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e2cde4cd280a3c55ae29a48de643ec25f94860e2914e6cb910f619e23e6f8e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2e2cde4cd280a3c55ae29a48de643ec25f94860e2914e6cb910f619e23e6f8e3
SHA3-384 hash: ea9c150fb90a38c596691cdbaed35e8d1298cd2904cad5c21fbd8d6edad148624e8ea6f5a252d64542ea4014ded7c052
SHA1 hash: f50f8c8f73e736e7e26a923a857411ad5bbed9ee
MD5 hash: 16a748d2510377478734bfc2e33becd6
humanhash: one-connecticut-georgia-salami
File name:Document536693.zip
Download: download sample
Signature AgentTesla
File size:431'243 bytes
First seen:2020-05-13 10:01:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:we0CJ7g+K3cIClhn8xRYYtVU5s0FBrVayrCbq9WnIJ3teQjFjxJEerwlxzd6ASdd:we0CJz9t25+O0FuqInIf9n8Vf5MVIG
TLSH C994230078B2317CF35A57A2EA77960EFB08F261F0527077BA079A51A75D832F992C35
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.jobrevolution.in
Sending IP: 103.93.17.225
From: Silva David<honsecretary@imma.in.net>
Subject: Copies of documents
Attachment: Document536693.zip (contains "Document#536693.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 18:58:00 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2e2cde4cd280a3c55ae29a48de643ec25f94860e2914e6cb910f619e23e6f8e3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments