MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a68063195e24c81ff5871a3f3c75053ca9a93131378da60609ac94134a1a5aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3a68063195e24c81ff5871a3f3c75053ca9a93131378da60609ac94134a1a5aa
SHA3-384 hash: 72fa211aab1507ac2fdd5cfc80c44207748fa523293b843d0cadbe568357348939f9e30f7373ff96349e42ea1e473904
SHA1 hash: e61a6b352b78f4c1b10010dc7779dc9985a3e080
MD5 hash: 148f75765e39dcd8263cd6a8f9132834
humanhash: three-fanta-alabama-uranus
File name:E-Remittance Copy.pdf.zip
Download: download sample
Signature AgentTesla
File size:390'110 bytes
First seen:2020-05-13 06:50:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:AW7bexYGl8wr+kgYJNAsBwDwXpS5RLmiFihvAwkrBKoQgEs3gGfzxH5V1K3+C9BN:r4YGl8y+aVs5RLJtGls/BhWxeu
TLSH 9B842382B2693A67E18EC8616681FB11F32273D01E31DC8FE53DDB55F1C8875EC12A69
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.bosemotors.in
Sending IP: 103.209.145.10
From: Jagath Sai <Straight2bank.sg@sc.com>
Subject: Re: Fwd: **TOP URGENT**E-Remittance Copy
Attachment: E-Remittance Copy.pdf.zip (contains "E-Remittance Copy.exe")

AgentTesla SMTP exfil server:
smtp.bethfels.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 04:06:46 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3a68063195e24c81ff5871a3f3c75053ca9a93131378da60609ac94134a1a5aa

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments