MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ff7c08013b3021cb330d6a3ffbced5725b4ba2354b4c16acb061f02c0bbe73e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7ff7c08013b3021cb330d6a3ffbced5725b4ba2354b4c16acb061f02c0bbe73e
SHA3-384 hash: ef17d4c8e3d2f29a1d07b92feb699d487cc285139f2ad7650161a1007100a3e54c0ac05f145ccfe4ffac9981674489e1
SHA1 hash: f77d0aa790bc4118c0e2a5c230366ce95143e3d2
MD5 hash: 3d5c764704c7b1a2b4add952b6521ba6
humanhash: lamp-avocado-fifteen-king
File name:BL.gz
Download: download sample
Signature AgentTesla
File size:569'220 bytes
First seen:2020-08-03 13:59:49 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:nCfm03ORIr+JbAfT3dlTuMblJ5Uh5aHDLbCsD5KV29ZzW:umcOiPf7dZjHWbaHDLOu7K
TLSH 20C4235F032FF7B59D87D168523C297B1B80C9E6FEEEA0D81A41A558F5D80123B89137
Reporter abuse_ch
Tags:AgentTesla Endurance gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: qproxy3-pub.mail.unifiedlayer.com
Sending IP: 67.222.38.20
From: Ana Cristina <anacristina.clavero@jci.com>
Subject: BL
Attachment: BL.gz (contains "BL.exe")

AgentTesla SMTP exfil server:
mail.eidtravel.com:587

AgentTesla SMTP exfil email address:
infobox@eidtravel.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 14:01:09 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 7ff7c08013b3021cb330d6a3ffbced5725b4ba2354b4c16acb061f02c0bbe73e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments