MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 74f3a95a6b25c67168406e39055f19adffeba312ae94e3c1b34294b918ecd1b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 74f3a95a6b25c67168406e39055f19adffeba312ae94e3c1b34294b918ecd1b5
SHA3-384 hash: bc12bf2a151aaf3118b326843a33782d8b3c075e059e91e96b141699b7d772c23dd6d269bd9b8f69398db401dd263239
SHA1 hash: 5b5a21d8a6005457055000acff2673548525d730
MD5 hash: 12953983990d8ffaac7e61de48467b2d
humanhash: mississippi-monkey-rugby-four
File name:APEMA INQUIRY 56709067.rar
Download: download sample
Signature AgentTesla
File size:416'601 bytes
First seen:2020-08-17 09:00:32 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:IiSIsmTly3+4QBGk6/KUsa7KiJXmQqHngSFIJN5uzzW98:FTkDjyJitmtgSFIJNYS8
TLSH 109423DC2ADDDA1392E347942F98B32650EDE7631E4DB849E02D89ED8A9E4D5E1CC40C
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: srv1000.cpeasydns.com
Sending IP: 52.117.216.21
From: Apema - Antonio Cardoso <purchase@mggreyengine.com>
Subject: Apema Inquiry 56707067
Attachment: APEMA INQUIRY 56709067.rar (contains "APEMA INQUIRY 56709067.exe")

AgentTesla SMTP exfil server:
smtp.blueskypaclficgroup.com:587

AgentTesla SMTP exfil email address:
bliss@blueskypaclficgroup.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-17 09:02:11 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 74f3a95a6b25c67168406e39055f19adffeba312ae94e3c1b34294b918ecd1b5

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments