MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ea12008a9425dbdee8c2d7808c6a57598c9c7a2f3814cd7f255f5c995b5afcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2ea12008a9425dbdee8c2d7808c6a57598c9c7a2f3814cd7f255f5c995b5afcf
SHA3-384 hash: 21967d185932e69439698bcf03d0cadbfb255ce06a132e181494559f70b2f90c27e10892e7b8c1eff028ec3bca925234
SHA1 hash: e5498dc0210571c89e2a5dc2930760b771cb63f1
MD5 hash: 96e392e49054c4357a92a6e1fb54064a
humanhash: paris-cold-texas-tennessee
File name:CT_8021947253523.cab
Download: download sample
Signature AgentTesla
File size:399'116 bytes
First seen:2020-05-25 12:47:39 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:3Pvqznsx4d/7LmwwgHh7Q9ca7qNPTZK+72deg:2sCmYH1QWhNNikg
TLSH 638423557216B3A4E6F738CDB6BA7908DCED97024C24888FEF376D518236BE07151A21
Reporter abuse_ch
Tags:AgentTesla cab HostGator


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gateway22.websitewelcome.com
Sending IP: 192.185.47.144
From: Gonzalo Ceballos <ventas@dabcon.pe>
Subject: SOLICITUD DE COTIZACIÓN
Attachment: CT_8021947253523.cab (contains "CT_8021947253523.exe")

AgentTesla SMTP exfil server:
smtp.megoagro.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-25 13:36:44 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
27 of 48 (56.25%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 2ea12008a9425dbdee8c2d7808c6a57598c9c7a2f3814cd7f255f5c995b5afcf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments