MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a9589f0354acee01fbbeaa15bcace06f38cac47af9f31d6335fd099ff0af8c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8a9589f0354acee01fbbeaa15bcace06f38cac47af9f31d6335fd099ff0af8c1
SHA3-384 hash: 3ce24f1b75026a4528f84a8d946506d7f9118ad5050469e6ed46c894c7c9066f8c9a3df63b6a6e17491a496b950155e9
SHA1 hash: fdbfd4936ed4ffe6d1c802bcf5b59567656ae9e9
MD5 hash: 89520519a6121f966098ca7d20301e51
humanhash: earth-queen-fifteen-utah
File name:345434543_PDF.GZ
Download: download sample
Signature AgentTesla
File size:382'944 bytes
First seen:2020-05-04 21:25:25 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:nHV1ywlG4VSniLRl9C5pqQn+OgrwA/6CPllaJXLKC6yyri7iqQ1OWBrAGlIzDoD0:HSwlGgZS7qQn+OgrRiCNlmLSLbqQVfm1
TLSH B78423E690EEA594341A12AF9150CC4FD53D32CD69C1ECB8CA0BB2922F6B5C5BFC9314
Reporter abuse_ch
Tags:AgentTesla ESP geo gz Santander


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.qrodi.com
Sending IP: 45.95.168.60
From: Factoring y Confirming - Grupo Santander<fyciout@gruposantander.com>
Subject: Confirming - Aviso de pago
Attachment: 345434543_PDF.GZ (contains "345434543_PDF.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-04 21:36:54 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 8a9589f0354acee01fbbeaa15bcace06f38cac47af9f31d6335fd099ff0af8c1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments