MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a95ad144039c290db25b51521df85a238955038e966edfe024194c152cc6508. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4a95ad144039c290db25b51521df85a238955038e966edfe024194c152cc6508
SHA3-384 hash: db1df3493cc76f23461c4bb32af2b03687674eb3fea13f1ee5fed03f1e46aee25a134c02a0d465a48feb13dce660693f
SHA1 hash: debac1b6e4fd762224e9e713f5a139b787626cb7
MD5 hash: 6a212a5f53c076c82ad272b9bd533777
humanhash: fourteen-may-happy-uncle
File name:SOA.zip
Download: download sample
Signature AgentTesla
File size:318'274 bytes
First seen:2020-07-02 07:14:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:dwNM7ROilUDkaMbwpI+GLNu/CrxWs5ET1xZq2HWP5kYKYBPoMrPfzJ:aNM7ROilUD1zXGE/CYTLZWqY+MjF
TLSH 196423A73392FE04B7F7B9ABEA4267A23F568171D20CC02C53A34B551B9527E7025743
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: redseatrading.com
Sending IP: 103.207.38.151
From: accounts@redseatrading.com
Subject: RE: OVERDUE PAYMENT
Attachment: SOA.zip (contains "9TJL3pzWGBA7xkb.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-02 07:16:09 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 4a95ad144039c290db25b51521df85a238955038e966edfe024194c152cc6508

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments