MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6f875eae7363d33fab127cb91dad4c7cb5135b7d49cf3ba372a5dd180611e65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a6f875eae7363d33fab127cb91dad4c7cb5135b7d49cf3ba372a5dd180611e65
SHA3-384 hash: f768d8f08cbbaa7ae168c3e91746394a8bb6f4faceb9249e6f2cc00b9e0d635221bd335241c593aa1c371649fe3d5e45
SHA1 hash: e2f449607512f11e9061bed3a5cbf040aefec1c4
MD5 hash: 3c9c0c76d81bf8a2c61def66df8fca17
humanhash: california-zulu-bluebird-asparagus
File name:Required Equipment Item AVP2-406890.zip
Download: download sample
Signature AgentTesla
File size:402'272 bytes
First seen:2020-06-08 06:52:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:1sLzezC256K5nqVawexGzIEJ8Zqm0MW81ksiUIaRFgx/llbWIv:Azezv5zgVawexEIEwqVg1ksi7x/jjv
TLSH 6F842362D8D766886758343DEC9517822F333B85EC89958F70203BC89F795752B3EA4C
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: se.servaidot.live
Sending IP: 45.95.171.205
From: Tomoko Kitano <infosemco-ltdt@gmail.com>
Subject: Re: Request for Quotation_PR#PS-AVP2-406890
Attachment: Required Equipment Item AVP2-406890.zip (contains "ah4HiGepeLiwtJI.exe")

AgentTesla SMTP exfil server:
mail.ab-care.eu:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-08 06:54:06 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a6f875eae7363d33fab127cb91dad4c7cb5135b7d49cf3ba372a5dd180611e65

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments