MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8db2ca2158bfaa69b4123a11c568a67ff2a6d38212636ad3a5b19c43486e9ddf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 8db2ca2158bfaa69b4123a11c568a67ff2a6d38212636ad3a5b19c43486e9ddf |
|---|---|
| SHA3-384 hash: | afa584ac49a559647a3588e80be5111304b65bfceaa93070944629631ba3089f77b85a3fedd82ddce8916dfb9e94cf76 |
| SHA1 hash: | 69329ee0b308b9465fb9ec2c0b99b75002c2c641 |
| MD5 hash: | 577447979fdae07a28f1c00df8bf9e80 |
| humanhash: | virginia-wolfram-sodium-pip |
| File name: | PO - 0002329.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 454'033 bytes |
| First seen: | 2020-08-19 14:11:19 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:2toCZO7qmoKAuqfej3ZNcPGZ3LGskJtIZlGNGDFD8dr1TreNmA2pKLnD1UlXNaCd:NWmoAqf6fZ7GztIZAUoE2pKf1Y7/sHA |
| TLSH | A6A42324EB43254AE35D513FF7A5CD133DE81F18E3BC99A206057DB0604D28FBA26756 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: yongjin.co.id
Sending IP: 103.133.106.25
From: Divya Aulia <divya.aulia@yongjin.co.id>
Subject: PO - 0002329 Bulk September
Attachment: PO - 0002329.zip (contains "PO - 0002329.exe")
AgentTesla SMTP exfil server:
mail.leffamatrizes.com.br:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-19 10:31:55 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.