MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77604552d9c830399f0a222341731296c9cc06226c0d343e080b19c5bea53cf2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 77604552d9c830399f0a222341731296c9cc06226c0d343e080b19c5bea53cf2
SHA3-384 hash: f19d207af2854fb83d4c7bd2c2c39004a0947a53adb2d9186ffd6f2bf56ecf69eb777937c5a86982f753ca8be24b33af
SHA1 hash: bb037d9af992dff089b05d5e9d7fd7e5613e67a6
MD5 hash: ef711398fa98c21391cba3e740846f88
humanhash: blue-carpet-florida-artist
File name:Payment Proof.zip
Download: download sample
Signature AgentTesla
File size:562'121 bytes
First seen:2020-08-03 13:00:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Yij2WyRGCO5KvcAqSNBjWrTzn2zaWpWlLH7PL51Bd:Yij2xRyMpqSNEDy+zj
TLSH CBC423714B77087BB529D6A251877822B29E20CB174AE7B3FBE341573B1C4B8C846F58
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sharp.co.kr
Sending IP: 103.99.2.5
From: 이주연 계장 (Joo yeon ,LEE)<jy_lee@sharp.co.kr>
Reply-To: sales04person@yandex.com
Subject: Prepayment Status
Attachment: Payment Proof.zip (contains "Payment Proof.exe")

AgentTesla SMTP exfil server:
smtp.taiemerica.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 13:02:07 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 77604552d9c830399f0a222341731296c9cc06226c0d343e080b19c5bea53cf2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments