MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40686840dbce762cb55abb99f9519218a1893ed0a7f7074f0fbc81c47bac157b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40686840dbce762cb55abb99f9519218a1893ed0a7f7074f0fbc81c47bac157b
SHA3-384 hash: 72adca8ca10da930e31bdf2f62ed103208b793b6280d919784859ee20cc86989da412990562e655030137dde481479a8
SHA1 hash: f09333836dc42a2433591dba3d8d60e978566d6d
MD5 hash: 3a446e018c704b64ea9abac23c58900a
humanhash: freddie-violet-thirteen-freddie
File name:INQUIRY.Xslx.zip
Download: download sample
Signature AgentTesla
File size:485'529 bytes
First seen:2020-06-03 08:24:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:BtljsKtgTn6+2oMaXoZNFHjdki6y25fbC8KwCLrA2Aw9:f1s6cn6+MaXqQia5f5K3Nt
TLSH 23A423C4678E5380F584F72E7E9F8FD72B98415D14029D5A1E0EBB2E78DA052BD31C8A
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: Rakzan.com
Sending IP: 172.93.161.29
From: Rakzan Ortis(Gr) <sales@Rakzan.com>
Reply-To: brianlee0147@yahoo.com
Subject: Dear pvargasnew inquiry
Attachment: INQUIRY.Xslx.zip (contains "INQUIRY.Xslx.exe")

AgentTesla SMTP exfil server:
mail.labombilladeoro.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-03 08:37:46 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 40686840dbce762cb55abb99f9519218a1893ed0a7f7074f0fbc81c47bac157b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments