MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abe72a52290291b40bddddb4a38c09e8922ce33b4d3a1fdcdb744ff1bb7fd261. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: abe72a52290291b40bddddb4a38c09e8922ce33b4d3a1fdcdb744ff1bb7fd261
SHA3-384 hash: b19de5756179fa747d9f6277b7f1da259025af1f7a80018bafd62dbe392644906355e368848369a2b0baf1d4bca4094c
SHA1 hash: 5dfe6f86e2cbcdbab02ca3e10bd01ffb9d6b4f3e
MD5 hash: c69bab612409407834937281fb667607
humanhash: edward-kilo-spring-iowa
File name:SAR EFILLING.Z
Download: download sample
Signature AgentTesla
File size:521'806 bytes
First seen:2020-05-21 10:06:41 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:FGDN2Q8l+UFb+YbGd4MbyM22Y1UdFQKpt:82Qh45PfS7Qyt
TLSH 01B4232E36140877C0E14A8523E82BE547B32EB1C6EAF03C5CFD9B51D26F26962F1B55
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: demm.duckdns.org
Sending IP: 185.144.159.163
From: noreply@sars.gov.za
Subject: SARS eFiling Letter Notification
Attachment: SAR EFILLING.Z (contains "SAR EFILLING.exe")

AgentTesla SMTP exfil server:
zstcznz.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-21 10:37:09 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z abe72a52290291b40bddddb4a38c09e8922ce33b4d3a1fdcdb744ff1bb7fd261

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments