MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fb8840bbe3bce6de6dc6c14171bbf8cab15811e5bdd3678e220c1823db0df49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6fb8840bbe3bce6de6dc6c14171bbf8cab15811e5bdd3678e220c1823db0df49
SHA3-384 hash: 3df665dd71bded228f892e4974ccc8846a3ef19e0d0252afcabc58dd04a9998273c21c7f7dcfc0ccc614efd47b9629dd
SHA1 hash: 43019fab11cb56412f1a1f4dfbc68fd0794c8100
MD5 hash: 5e57e772f184e36ddf796517e82e0d76
humanhash: low-louisiana-utah-nevada
File name:TNT shipping details_pdf.r00
Download: download sample
Signature AgentTesla
File size:228'238 bytes
First seen:2020-05-21 08:12:24 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 3072:mlvxt6mYD7hiG5ESKWI3JxgZO1lEFv39LGWsF8up2rdhkrVGtACIoj14OaQJ9vjH:CfqXd6nDEN39q9DpghAMpVnJpz
TLSH E72422913C089353208D547097EEE35FF726408B723655E44ECC87A0AEBD9ADD532F6A
Reporter abuse_ch
Tags:AgentTesla r00 TNT


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zeus.riff.ro
Sending IP: 81.180.116.49
From: TNT EXPRESS <support@tnt.com>
Reply-To: supply@tnt.com
Subject: TNT Delivery Notification:Please update your shipping details
Attachment: TNT shipping details_pdf.r00 (contains "TNT.exe")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-21 08:36:22 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 6fb8840bbe3bce6de6dc6c14171bbf8cab15811e5bdd3678e220c1823db0df49

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments