MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75748dc6f74605be189c04762122e9a92b9bd19c6a74fc0dcb1706653e4fa01d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 75748dc6f74605be189c04762122e9a92b9bd19c6a74fc0dcb1706653e4fa01d
SHA3-384 hash: 917a742665d53cbfce15ce25635a1286aaefd5a822073b58857d0b074bc93dc99d488ef6d54d909c0017ca1f3807568f
SHA1 hash: 99063f1652fc85ff2e4a76d889c12e8c30edce85
MD5 hash: c610c2eddd41e9d84c18d22256019ab6
humanhash: equal-quebec-batman-kitten
File name:Purchase Order 20050026 - ASIK008720.img
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2020-06-16 13:17:14 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:1f+0Yzc9jPtV2YzVYhScc7nRZ4lzaSmaR:1G0YARIYzVYhtIj4FaqR
TLSH 1B65010D67AC6235D3BC4A3C85F225044BF8B8677512EA19BE8932ED1F237D24A52E47
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: giconindia.com
Sending IP: 37.49.224.45
From: Priyanka <proposal@giconindia.com>
Subject: Purchase Order: 20050026 - A/SIK/0087/20 - 20200131 Dt. 14.06.2020
Attachment: Purchase Order 20050026 - ASIK008720.img (contains "Purchase Order 20050026 - ASIK0087201.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-16 13:19:04 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 75748dc6f74605be189c04762122e9a92b9bd19c6a74fc0dcb1706653e4fa01d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments