MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8d27b3abd4deefc22f25185095ae7718b2eb52ba563d68cc687b49f216820a16. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8d27b3abd4deefc22f25185095ae7718b2eb52ba563d68cc687b49f216820a16
SHA3-384 hash: cebdaab82d239815025cdad17477e808753113cf8ca7fb8282aedf5ecd2be6b0750c8e348dd31451785b5dd51b76a02c
SHA1 hash: db2f9c7911c642adc1aa40e108a9657503e4ea42
MD5 hash: 1bca6f9ba38960040adb64ce6a653b9c
humanhash: muppet-black-low-cardinal
File name:SUL-MR-MS-0005 Silo.rar
Download: download sample
Signature AgentTesla
File size:526'950 bytes
First seen:2020-08-05 09:15:26 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:RqRXp+mDit7M6VqtsV1VceEqCcXYO4BOs8Prk+a:RKDiqtsTVceE+YV84b
TLSH 1FB42321753FF6CF1C6A3B6F0FD0FB5CAB02D95602E6744925E602359A94FB942EC182
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: xa0.24.msllownpl.cf
Sending IP: 46.101.97.155
From: Byoungsoo Min <kaimin@hec.co.kr>
Subject: [LINE] Inquiry of Silo for Sulfindo VCM/PVC project in Indonesia
Attachment: SUL-MR-MS-0005 Silo.rar (contains "SUL-MR-MS-0005 Silo.exe")

AgentTesla SMTP exfil server:
mail.sinantombul.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-05 05:56:37 UTC
AV detection:
18 of 27 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8d27b3abd4deefc22f25185095ae7718b2eb52ba563d68cc687b49f216820a16

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments