MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5160c56c14f86e4b0428d90f66ea56bfea8a06c127c437dd491c74882d120bef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 5160c56c14f86e4b0428d90f66ea56bfea8a06c127c437dd491c74882d120bef
SHA3-384 hash: b5a52051bec7e0cce5c26d439cc2822300f92fe0b89179eebfa41deaf19b08bedea684338b488a9916e1a6a7094cf3b6
SHA1 hash: e2b0aa644e1bc460e4a64fca873e8e3f149575e8
MD5 hash: 82d0644c7ffa60c8b20ef6e7f03193f5
humanhash: fruit-november-pennsylvania-king
File name:Purchase order 202.rar
Download: download sample
Signature AgentTesla
File size:405'435 bytes
First seen:2020-05-25 12:36:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:AzIAFQObLV6x2wZzQTGs63ZQFqBQrwZmJ8b5u7i7uYewLpkur0:cTcZzvZQYvKvH1ApfQ
TLSH 1D84234F5A1F6841F9021DC183D4FF91DEC62C7C5A3156682AA35D723F8FA46E07A0AB
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Raghu Texcoms <raghu@mail.texcoms.com>
Subject: Re: Purchase order #202
Attachment: Purchase order 202.rar (contains "Y2eV6TiLHp3CuY1.exe")

AgentTesla SMTP exfil server:
webmail.pat.ps:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-25 13:36:47 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 5160c56c14f86e4b0428d90f66ea56bfea8a06c127c437dd491c74882d120bef

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments