MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7ff5be3211df050ad086986b11dff78c88bbc54e2c08d4f18752cf0e291e1f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a7ff5be3211df050ad086986b11dff78c88bbc54e2c08d4f18752cf0e291e1f3
SHA3-384 hash: caedca9cebc9d6cf6033b4547fcf9d047b1e4af82443e47d2e3e8e840ecf53fda7f5ed5d1a551ed62014137aa03c1723
SHA1 hash: 061dea74a323dfb4c6f1e0698b1516694b198b40
MD5 hash: 9e01fdcb01584f9fe74fd49ad5de223c
humanhash: london-idaho-football-spaghetti
File name:OUTSTANDING PAYMENT STATEMENT OF ACCOUNT MARCH TILL DATE pdf.zip
Download: download sample
Signature AgentTesla
File size:395'213 bytes
First seen:2020-06-26 15:35:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:XxR5bS6emfT/HGtR5zOiBPZtA84zLq7rTksj4ITxR609fZ4f25o1TivrV1/LwJWS:hHbHfrgzTFTHT3jb/1ffm1T+rry1
TLSH 908423F661185201B296A8B20245E265EF47563B20BB88F0FD8597F0DD1AE7B3F508F7
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chemspec.co.in
Sending IP: 103.145.255.117
From: rajesh.k@chemspec.co.in
Subject: FW: OUTSTANDING STATMENT OF ACCOUNT BEFORE MAKING PAYMENT MARCH-JUNE
Attachment: OUTSTANDING PAYMENT STATEMENT OF ACCOUNT MARCH TILL DATE pdf.zip (contains "WanvTh7JU7Wk7rS.exe")

AgentTesla SMTP exfil server:
mail.macrosyselectronics.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 15:37:04 UTC
AV detection:
22 of 30 (73.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a7ff5be3211df050ad086986b11dff78c88bbc54e2c08d4f18752cf0e291e1f3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments