MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8da845fdd62a85d767317c6253877f5262fe2a6e307023a508c309ee04c1bcb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8da845fdd62a85d767317c6253877f5262fe2a6e307023a508c309ee04c1bcb6
SHA3-384 hash: ad5e2ebffd1319dc8d14b07474068ac18c7daa0c98fe29a4fcb1a15df7348c30cdc54cf74ef2328c04aabff1e7d2802f
SHA1 hash: 0921c1a0e652907ce2ac01e8dc909af045a28cd7
MD5 hash: 9d916d2bf4fe54b1a42916e2a138c18b
humanhash: diet-pluto-california-twenty
File name:Quoted INV-15BDO.r00
Download: download sample
Signature AgentTesla
File size:424'720 bytes
First seen:2020-06-18 10:12:56 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:b+KMhSYx3nY85suEDtcy88VMq8jnX9AkJfveOfNv:CjSInYiED88qqWX6UOOVv
TLSH 3B942357A3708631D96A890CBCA6A23115BFFBC6FC68A8731845D987D4F32217BDF060
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: imail.de
Sending IP: 95.211.208.50
From: ACCOUNTS <leonid.pidorovich@imail.de>
Subject: RE: Quoted INV-15BDO
Attachment: Quoted INV-15BDO.r00 (contains "Quoted INV-15BDO.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-18 10:37:24 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 8da845fdd62a85d767317c6253877f5262fe2a6e307023a508c309ee04c1bcb6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments