MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 349a6ef8d65c119effa575173e9a644ed4aa34ea7b2c96a17b6170cbf8d76f88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 349a6ef8d65c119effa575173e9a644ed4aa34ea7b2c96a17b6170cbf8d76f88
SHA3-384 hash: 6d874ea2647031eebf13a37d91019b449566fcb1cad7788e277576ea7744bc3724a8a4874dbef6533ac95edba1859869
SHA1 hash: 0d57437997723869eb2f0836c870c7bf53708c9f
MD5 hash: 3bbff04fd85f8d796b5bee4f167c41a6
humanhash: eleven-queen-saturn-jersey
File name:New Order.zwa.zip
Download: download sample
Signature AgentTesla
File size:395'750 bytes
First seen:2020-05-11 14:27:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:QLXPaT8RhuBPTmlnG+WAYtuqE45O64tHuCD:QDPaT8Rh2lLtpZuHuCD
TLSH E884239456E1CA9B3D8F5D42BF8D90C9A3DFBD216095819C3ACEB480D6F47FB0059B0A
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mout-xforward.perfora.net
Sending IP: 82.165.159.134
From: Sales Dept <info@nemecserver.net>
Reply-To: Sales Dept <info@nemecserver.net>
Subject: New Purchase Order COD-653EDV
Attachment: New Order.zwa.zip (contains "New Order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 14:36:55 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 349a6ef8d65c119effa575173e9a644ed4aa34ea7b2c96a17b6170cbf8d76f88

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments