MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f0e3834d6a12baa3e46420af1f343225ce349b8641161d33d62341666f37106. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9f0e3834d6a12baa3e46420af1f343225ce349b8641161d33d62341666f37106
SHA3-384 hash: 1ae6f25357257b3c5f7ef64d96618cb76abc92ca36aa8c51f846c6137db8e572e2edc8b862d5a80e9584caf9c13f3177
SHA1 hash: f5fdfdac8b7dd3e65231115d351db0dd1e6e94ce
MD5 hash: 66ec93d2f9153a934e1d98ffa39c2099
humanhash: johnny-georgia-michigan-november
File name:518202380100091.exe.zip
Download: download sample
Signature AgentTesla
File size:332'552 bytes
First seen:2020-07-13 06:31:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:BoqAuG3d+FeqLamyKg1J3H4/S+CdrEp9fkv0aEDlX8D5pym:63UZLamELYzf/8lph
TLSH E0642361FCF0D13CD74B1251537DFA0BCB446BA94A9E249B7810E6F9DB0E81EE6B2811
Reporter abuse_ch
Tags:AgentTesla Endurance zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 142-4-22-49.unifiedlayer.com
Sending IP: 142.4.22.49
From: Aleong, Rebecca <pgne.documentation@oiaglobal.com>
Subject: Incoming Payment advice-BG_EDG7602020062601480045_423_761
Attachment: 518202380100091.exe.zip (contains "518202380100091.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-13 06:33:04 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9f0e3834d6a12baa3e46420af1f343225ce349b8641161d33d62341666f37106

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments