MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ad3b94ffad93236d188ccb2c70b6436d48e6ea2a3fcdcc30eaa395bd838341f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8ad3b94ffad93236d188ccb2c70b6436d48e6ea2a3fcdcc30eaa395bd838341f
SHA3-384 hash: c4463b94b3ae7612b8499c63be16af038d1bec5ea3f5469327ac2a52ef30a9666e292f0129011a34e2c070f7867ecd07
SHA1 hash: 28c8cd44798a558a0f4802559361feeca69e2a98
MD5 hash: e3c56b3289938cc743aa20eb1cbbd307
humanhash: mexico-river-summer-august
File name:RFQ – Road Construction And Drillingdredging equipments..img
Download: download sample
Signature AgentTesla
File size:1'572'864 bytes
First seen:2020-08-27 08:47:43 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:AXdgseMnCyDA4vlAqJhLvojGtP4EpxX9sdJ+wm:Atg8RvlB/Lt5Nsd0
TLSH 1975BFB5C31BCB6CDD0472F860724869E5336E56EA3491D8EE0FB0F47B7714A602998E
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kkj5.gianthosters.com
Sending IP: 23.128.128.3
From: Alhmmed Esmali <asmaeel_@arconqatar.com>
Reply-To: project-tech@arconqatar.com
Subject: RFQ – Road Construction And Drilling/dredging equipments.
Attachment: RFQ – Road Construction And Drillingdredging equipments..img (contains "RFQ – Road Construction And Drillingdredging equipments..exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-27 08:49:07 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 8ad3b94ffad93236d188ccb2c70b6436d48e6ea2a3fcdcc30eaa395bd838341f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments