MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a2de75bd212c3e8f5c1695819f8d26c413760b56714f52e80bb65322588aca9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | a2de75bd212c3e8f5c1695819f8d26c413760b56714f52e80bb65322588aca9b |
|---|---|
| SHA3-384 hash: | 34dc00f84dc62f60fc63b7fe497413a053f05dfcf9bf8523f1adc92cb832dece09a98bff8ef1fc63ebe3b1eeafbc2366 |
| SHA1 hash: | f23290392ef3bc8f85495749ac4e781578bb041d |
| MD5 hash: | 5ed34bfd2123a86a9e7a4b8efdfbcc68 |
| humanhash: | arizona-pennsylvania-romeo-freddie |
| File name: | P O...zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 547'771 bytes |
| First seen: | 2020-07-28 14:14:53 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:aAdpzxT8MLA2DQjq2Gqw10/jo+sCpNOVV12mMZEM8:DDtBAQYMn+sCps0JZEt |
| TLSH | 94C42352087A18F8C2F916C2577985F18F021B24EDB449F8732BF1855BEA060EE2D5AF |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: ghhaewae.com
Sending IP: 103.99.1.143
From: Shohrab <shohrab@ghhaewae.com>
Subject: FW: [BULK] IDFL20-312820-821 Samples Received Confirmation
Attachment: P O...zip (contains "P O...exe")
AgentTesla SMTP exfil server:
mail.mystboutiquehotel.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-28 14:16:09 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.