MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fd8d3cad2c96011d7a325a8ccd7e9e1fe63cd064b4bfa53378b4d0f5469f79c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2fd8d3cad2c96011d7a325a8ccd7e9e1fe63cd064b4bfa53378b4d0f5469f79c
SHA3-384 hash: fc5a6dc345c305c778f533aef9f67af4dd6e6298902535d647e373546a8af07ebb7f7ec54bcb07e86e66fd3d22c0284f
SHA1 hash: 9a4982e1e4e72a919a202fd8bee6bdaffbff28ff
MD5 hash: 5cdb07636f0a7c277959b308910bfcb9
humanhash: mars-vegan-zulu-oscar
File name:box_akt_kaisar.zip
Download: download sample
Signature AgentTesla
File size:381'553 bytes
First seen:2020-05-06 10:40:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:qGZfyVs8bGxV4OmyZb0ixKQOLgJN4nUCilke2tvjFN4RflSRtHthR8hGRHM:pZIsaq0yZIOD3TlT25jLLRtNvRHM
TLSH 1C8423274F596EE79E37485B5333B4E32155C2FAEA8923753E9706E092E366CB0042B1
Reporter abuse_ch
Tags:AgentTesla MailChannels zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: relay.mailchannels.net
Sending IP: 54.214.232.113
From: Mauritius Kaiser <xpoixyz@xpoi.xyz>
Subject: WG: RFQ box
Attachment: box_akt_kaisar.zip (contains "box_akt_kaisar.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-06 08:55:25 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2fd8d3cad2c96011d7a325a8ccd7e9e1fe63cd064b4bfa53378b4d0f5469f79c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments