MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bd72163fc73ee7b68d3b9d625458642f5eca77c2bf18b60492256fc92370a61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4bd72163fc73ee7b68d3b9d625458642f5eca77c2bf18b60492256fc92370a61
SHA3-384 hash: d5f288ca86364476f8631c687899b5eb354d7bc3807cded8efe5e48050264728490fe12ae3f54d42a37a858d94f0a3a9
SHA1 hash: fa1679490b4c6f0afaa67f62412f76292162c1dc
MD5 hash: 9c58771f0b6fcd7467047b2471f4921d
humanhash: shade-kentucky-whiskey-avocado
File name:Dwg-8710.00.9000.rar
Download: download sample
Signature AgentTesla
File size:436'019 bytes
First seen:2020-06-08 05:52:31 UTC
Last seen:2020-06-08 05:59:32 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:81suCW3J66zPu6s8X46Em6btUweuiTl26ajYuxnJKhYtCjLVRVIr6MIgfKlXj:81suMMPps8XuTvjYuZGYIjVMIg4Xj
TLSH 4994235D6D0E1DFAE12B1F402439AA671C6CCC5672E09683E89E9B1C24DAF7318D16F2
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.577.zizospanltd.casa
Sending IP: 68.183.92.251
From: millenniumship <kachungj@millenniumship.co.kr>
Subject: vessel from Eilat,Israel to Busan(or Masan),Korea. 2TEU of IMCO Class 1
Attachment: Dwg-8710.00.9000.rar (contains "Dwg-8710.00.9000.exe")

AgentTesla SMTP exfil server:
secure197.inmotionhosting.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-08 05:54:11 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 4bd72163fc73ee7b68d3b9d625458642f5eca77c2bf18b60492256fc92370a61

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments