MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0cdbfcf2ba6038432a7b7b52b9934bffa1afb44e4c25f0ca04cc288574da513. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a0cdbfcf2ba6038432a7b7b52b9934bffa1afb44e4c25f0ca04cc288574da513
SHA3-384 hash: 50e13287daa078851cd9b8e544f9e60162dc5169db1dfd8ded7639127c8199443e21ffafd8807b5fec36a3a26ebff911
SHA1 hash: 314ce1483394e1854e6b5cf111e7798b71b75ea6
MD5 hash: 0a68e8a30c29bc26c25f7831720206ce
humanhash: blossom-pennsylvania-colorado-artist
File name:INVOICE7263_PO.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-12 16:33:36 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:H+R4o6Pi2F9eoc/4+5PoO671h9c0Cn/5t4OOow3MI9/:K2zx2pAR85tjOzMI
TLSH B945E0377298EE03F24E73FA94926006C3B19D526492E3873DCE7ED916B57C10682D9B
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sip1-210.nexcess.net
Sending IP: 209.126.18.195
From: MONICA LEE <noreply@stunningireland.com>
Reply-To: infojanboy@yandex.ru
Subject: CONFIRM FULL PAYMENT
Attachment: INVOICE7263_PO.IMG (contains "SCTB7263_PO.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-12 19:56:57 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
14 of 31 (45.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img a0cdbfcf2ba6038432a7b7b52b9934bffa1afb44e4c25f0ca04cc288574da513

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments