MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ff6d43fd3dbad05dc60a83a3d945734c8eb756081d6bf27a91743256cfd9284. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3ff6d43fd3dbad05dc60a83a3d945734c8eb756081d6bf27a91743256cfd9284
SHA3-384 hash: af60621c23b668f947f0d645d93ec03b715c948298e8f7aa780c7c16599190e05fa9da72573deb69f249e130fc17759f
SHA1 hash: 4abf7df9648ac3fcdbcfb54e41accc488c5355cc
MD5 hash: d99bc741ac4cf9dbe47039a2eb0456ba
humanhash: mango-two-wolfram-hotel
File name:New order.gz
Download: download sample
Signature AgentTesla
File size:487'169 bytes
First seen:2020-06-03 11:21:09 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:cLw76FaZVV5mOpEOYEc7Dpr9HWqydpS852bGa:T6SOOpgr92qydr2qa
TLSH 6DA423BD198EF935E5097E0745B349EACE62C51C20B77D2091AD92ABAE3C1785DCEC30
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.bontechnologies.com
Sending IP: 46.4.133.15
From: marketing <marketing@prpexports.com>
Subject: Re: New order
Attachment: New order.gz (contains "New order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 11:37:33 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 3ff6d43fd3dbad05dc60a83a3d945734c8eb756081d6bf27a91743256cfd9284

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments