MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2de75bd212c3e8f5c1695819f8d26c413760b56714f52e80bb65322588aca9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a2de75bd212c3e8f5c1695819f8d26c413760b56714f52e80bb65322588aca9b
SHA3-384 hash: 34dc00f84dc62f60fc63b7fe497413a053f05dfcf9bf8523f1adc92cb832dece09a98bff8ef1fc63ebe3b1eeafbc2366
SHA1 hash: f23290392ef3bc8f85495749ac4e781578bb041d
MD5 hash: 5ed34bfd2123a86a9e7a4b8efdfbcc68
humanhash: arizona-pennsylvania-romeo-freddie
File name:P O...zip
Download: download sample
Signature AgentTesla
File size:547'771 bytes
First seen:2020-07-28 14:14:53 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:aAdpzxT8MLA2DQjq2Gqw10/jo+sCpNOVV12mMZEM8:DDtBAQYMn+sCps0JZEt
TLSH 94C42352087A18F8C2F916C2577985F18F021B24EDB449F8732BF1855BEA060EE2D5AF
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ghhaewae.com
Sending IP: 103.99.1.143
From: Shohrab <shohrab@ghhaewae.com>
Subject: FW: [BULK] IDFL20-312820-821 Samples Received Confirmation
Attachment: P O...zip (contains "P O...exe")

AgentTesla SMTP exfil server:
mail.mystboutiquehotel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-28 14:16:09 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a2de75bd212c3e8f5c1695819f8d26c413760b56714f52e80bb65322588aca9b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments