MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 479669edf677f1d101d792bce3956084d68e34a7df8f6ea87d4838230f07e4b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 479669edf677f1d101d792bce3956084d68e34a7df8f6ea87d4838230f07e4b4
SHA3-384 hash: 2f5f39cf200dd82a41fd670058d1381224cfac44d43e82a500d36b57dcaef72904ac4b4e94816cf58c800439d2840cac
SHA1 hash: cf8c26ce6f6bc15d2242d0f20dfa848af034bee1
MD5 hash: 1fc94f70d010ca6b3a9d591c74b1aa85
humanhash: white-jig-high-lamp
File name:080899090800.z
Download: download sample
Signature AgentTesla
File size:467'400 bytes
First seen:2020-05-08 08:18:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:cBDGa97bKMnjq+mJ9JFjhuN740/iVXcbk7FWm5b//qOXHPSzRy+wzdlBfuh30/ba:EH9bmJVuNk0/jb8gmp/NHVRffdbL6r
TLSH B8A423D5C1F0C09F5CF4D0E0BC6CB35A44242D2B5762499453EA8D67C61B6E29E2E2FE
Reporter abuse_ch
Tags:AgentTesla geo THA z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: koata.serveriai.lt
Sending IP: 194.135.87.121
From: info@dmsinc.com.tw
Reply-To: info@dmsinc.com.tw
Subject: ใบแจ้งหนี้การชำระเงิน -090900
Attachment: 080899090800.z (contains "080899090800.exe")

AgentTesla SMTP exfil server:
smtp.ionos.es:587

AgentTesla SMTP exfil email address:
postventa@blutech.es

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-08 08:36:06 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 479669edf677f1d101d792bce3956084d68e34a7df8f6ea87d4838230f07e4b4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments