MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 716ab112537c70d1c9f4b8a8ceb2e3799964836d026b15ecc1d9634c7d1bdbbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 716ab112537c70d1c9f4b8a8ceb2e3799964836d026b15ecc1d9634c7d1bdbbb
SHA3-384 hash: 2644b7b727482d52a1562767b1569af5ff1bf13f491a9917abd2745cf75c0b81172f1edaaaab7269aa8099dce7ebda67
SHA1 hash: e8a9a43b5c07a8e8185f9906acad6d516bb1baae
MD5 hash: 729a8baa86e3901bd42ac361e8d8215c
humanhash: early-snake-march-delaware
File name:BL Payment Swift 20040295_PDF.r02
Download: download sample
Signature AgentTesla
File size:417'026 bytes
First seen:2020-05-11 14:42:31 UTC
Last seen:Never
File type: r02
MIME type:application/x-rar
ssdeep 12288:Bndr/NpYA5aXErrRRuti0HKHw+VcR3qGjkx8:BdrlOA0MdHw+SRW8
TLSH FF9423F0AE79FBA3CD65B7CB2D1BF0753EFADDA2114AA05B09D74058E400224B936365
Reporter abuse_ch
Tags:AgentTesla r02


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: achilles.noc.ntua.gr
Sending IP: 147.102.222.210
From: KangQian Wong <rs12704@central.ntua.gr>
Subject: Balancing Payment Quote SSL-20040295
Attachment: BL Payment Swift 20040295_PDF.r02 (contains "BL & Payment Swift 20040295_PDF.exe")

AgentTesla SMTP exfil server:
mail.candenizcilik.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-12 02:26:00 UTC
AV detection:
13 of 31 (41.94%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r02 716ab112537c70d1c9f4b8a8ceb2e3799964836d026b15ecc1d9634c7d1bdbbb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments