MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9eb0fe3160b318e11c20a7c50a366bafff83179fb1b2b7da61dc364e9001b5be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9eb0fe3160b318e11c20a7c50a366bafff83179fb1b2b7da61dc364e9001b5be
SHA3-384 hash: beb7bebf1fcf88cce3a0b5ee718faf8515dd9aa9bd43d1052b284a79eb9fa16e6f8ef16db576812faed0c3493b9ebaf0
SHA1 hash: feca3bc8c812194895ff796584608c88955edb02
MD5 hash: 5902070f9df243750704373db419f85d
humanhash: snake-oranges-nevada-hotel
File name:CHECK PEA-SPM2-TDDP9.zip
Download: download sample
Signature AgentTesla
File size:332'372 bytes
First seen:2020-05-18 07:28:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:UJJM6VUY60Tae2rwvuUBM+z3qdPocdDXBZGzIiXKPtWfeX/+bCSFpkqKsehqVZ:U605Fdl38bjBZGzjXKYfekCK7ohK
TLSH C264231539620C42B4ADFD65FB29CE88E7E2F60E5697018FE9C08CA8D7BFFC95805149
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 156.96.59.92
From: "Tippawan Nopsanoi "<sriuthong@gmail.com>
Reply-To: legitworld04@gmail.com
Subject: AUGENT QOATATION FOR Bid No. PEA-SPM2-TDDP9
Attachment: CHECK PEA-SPM2-TDDP9.zip (contains "CHECK PEA-SPM2-TDDP9.exe")

AgentTesla SMTP exfil server:
smtp.na-superhrd.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-18 07:35:42 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9eb0fe3160b318e11c20a7c50a366bafff83179fb1b2b7da61dc364e9001b5be

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments