MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9231da34ee6d5a4d4ebe684cb21756c3b2052f092297b9fb6231d6d8935542a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9231da34ee6d5a4d4ebe684cb21756c3b2052f092297b9fb6231d6d8935542a2
SHA3-384 hash: 0201714fa193a2ac3f0b1c5302c0b82519701a39ad9b875d20079b32ad9c2a8f3ee2f571f61feecb90646d64055e4a30
SHA1 hash: 6c6ec78e102403f322dd563ec18d831cd45c5c2e
MD5 hash: 2f5c32fac095971393477247e0ab649a
humanhash: tango-two-iowa-lithium
File name:receipt copy 000201106012020.7z
Download: download sample
Signature AgentTesla
File size:480'131 bytes
First seen:2020-06-02 10:34:42 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:Id7FxGHsJl6iuZRCl0sCvqPZWGJDdXXaHPTm:IdXrJcimRCl0NvohtFKK
TLSH 5FA4235E9BDB130FB3A426B3C2722D5E185FB7AC32B449F666D0A86059E553C300A74F
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.processing.ro
Sending IP: 86.107.224.178
From: Clive Pratt <clivepratt30@gmail.com>
Subject: Copy Of Invoice
Attachment: receipt copy 000201106012020.7z (contains "receipt copy 000201106012020.exe")

AgentTesla SMTP exfil server:
mail.ductoslimpios.com.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-02 10:37:12 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 9231da34ee6d5a4d4ebe684cb21756c3b2052f092297b9fb6231d6d8935542a2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments