MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 593fb1a7dd2f1376308a1ff2bc8a4f656334a4a55164e042bf437f3ad74efd26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 593fb1a7dd2f1376308a1ff2bc8a4f656334a4a55164e042bf437f3ad74efd26
SHA3-384 hash: 85003b8189d4ac52685263eeb7a2325b8ea30dc61fbfa3f0d9b262c0ddf92861f0e7f0882eedd00260258455c7be979d
SHA1 hash: f1c06e8ad844ef58dfcd1cab9d60501bd8c3af3d
MD5 hash: 2ada88f75c4549159fa846dd8b5a0c7c
humanhash: uniform-football-september-xray
File name:TOP URGENT INQUIRY 2020.7z
Download: download sample
Signature AgentTesla
File size:458'660 bytes
First seen:2020-05-20 08:37:48 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:ZloNi1WhMAvUPwYPXGK71/DNoUd35LsjVusxUFKo:Zlt1WeAsIYP2IJDNFZV8Vusx0
TLSH 92A423BC12BDC2A9C022D1F5D72AF413DF37A69FA827874616931C9327528A3D41CB5B
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.websitetestingtoday.best
Sending IP: 79.124.8.124
From: Kim<jw021@126.com>
Subject: 2020 年 緊急 事件 查詢
Attachment: TOP URGENT INQUIRY 2020.7z (contains "Order -plastimol.exe")

AgentTesla SMTP exfil server:
premium12.web-hosting.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-20 09:36:08 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
15 of 30 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 593fb1a7dd2f1376308a1ff2bc8a4f656334a4a55164e042bf437f3ad74efd26

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments