MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54729975dd028ec6b2f17f92cdd42fbeba196979629afa6af4e43c8e37446081. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 54729975dd028ec6b2f17f92cdd42fbeba196979629afa6af4e43c8e37446081
SHA3-384 hash: 0d984977c46d044a5d343dd67bd80c8b60064274ef6b0cbf15a6c2cdd85d5afef569c187ec15d94bdb6b2a67f2604a3f
SHA1 hash: 1b46800f407bdaf770185fb50a90ccc93897b231
MD5 hash: 4708b0d7508f58f51960b8e030bd620e
humanhash: high-chicken-tennessee-december
File name:RFQ.zip
Download: download sample
Signature AgentTesla
File size:424'113 bytes
First seen:2020-06-03 10:10:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:jeSvIWwAxMssylRVpuMxj2Z3xJKkFiDIWr1K6s6ohO46F:SSgA/VIMxj2ZZWJK6s65
TLSH E09423A8F994F25E26CA613AA753C0F35E2CF231BFA4E17C111D3152F174646BA8780E
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pro42.emailserver.vn
Sending IP: 103.15.48.69
From: wh@chungmo.vn
Subject: Quotation for Supply
Attachment: RFQ.zip (contains "ZXWhx90mUqQDbDY.exe")

AgentTesla SMTP exfil server:
smtp.forapro-ru.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 10:36:31 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 54729975dd028ec6b2f17f92cdd42fbeba196979629afa6af4e43c8e37446081

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments