MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3fef976c993a06345a2d929d5b3cd20c55f36a6754e36934c1864f191a59b7ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3fef976c993a06345a2d929d5b3cd20c55f36a6754e36934c1864f191a59b7ce
SHA3-384 hash: e21b266923f6b1f3beb3b651b5ca27ea4ac0c001fa92d00f8e0e0618b4730c8273f2c0d1eae7b883f8ebf6c27aa7d890
SHA1 hash: 29414015aa7172ee0d51ce65e7a50a403098eac7
MD5 hash: d7fc4e0bba2c22386fbba37611a0b84d
humanhash: robert-september-failed-comet
File name:Q0001DA Payment.rar
Download: download sample
Signature AgentTesla
File size:399'394 bytes
First seen:2020-07-08 13:00:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:ImCXdlZ/I2SA+9mx5vLjUUAIkIdLJmkvRj87jXv1HuWZcvaNzBjb+qRX:Im6Z/hd+Yp3U6xdV87xZWvaNzBX+qN
TLSH 4E842389357257F3223E35D8B7F2257A0C198AFC6716406B64DE27CA3D14284ADCE86B
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ngay7.localdomain
Sending IP: 45.127.62.196
From: "Amahle Bokamoso"<durgan@hiluu.com>
Reply-To: <bonqanim@gmail.com>
Subject: Re: Proforma#26402-Lr.No-2034163
Attachment: Q0001DA Payment.rar (contains "Q0001DA Payment.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-08 13:02:06 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3fef976c993a06345a2d929d5b3cd20c55f36a6754e36934c1864f191a59b7ce

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments