MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 42a3e98cca517cb3cc670c9ed9fc0b17d3b60e63499ee46ea6d6c22b2ff0d126. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 42a3e98cca517cb3cc670c9ed9fc0b17d3b60e63499ee46ea6d6c22b2ff0d126
SHA3-384 hash: 02aca0c0a2eeaa606bb8c9862c1c947241ce73a6bf8ab6355339a2ece9d5d3928ca25906dc4978fc2327b2f673484b84
SHA1 hash: fd9d606d4c1148559b850bf426886f0786ffae4c
MD5 hash: 8f4c9fc2a975f184b6a473d23b63bf1c
humanhash: spaghetti-ack-golf-pluto
File name:REQUEST FOR QUOTATION.zip
Download: download sample
Signature AgentTesla
File size:455'167 bytes
First seen:2020-06-18 19:49:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:hopOfiVwgNTMEHJpFgAXj/G1aSElXbwvdTCqNTO:ypxwOQEHJpFPXIaxXbmCaO
TLSH F3A423921280A3396F989C0F5530E78B354B34D425A74852B6FEEF0AD3C7B90F9D67A1
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.chronicgames.biz
Sending IP: 45.95.169.105
From: info@chronicgames.biz
Subject: REQUEST FOR QUOTATION
Attachment: REQUEST FOR QUOTATION.zip (contains "uPzEcKikmnRh2Eh.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-18 20:35:38 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 42a3e98cca517cb3cc670c9ed9fc0b17d3b60e63499ee46ea6d6c22b2ff0d126

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments