MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac309a343529c9ad2729aaf77975aade30b1a3e2e4d7360ed6cc054f17ddef58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ac309a343529c9ad2729aaf77975aade30b1a3e2e4d7360ed6cc054f17ddef58
SHA3-384 hash: 8f78a9aae610532c367de542cdc72a54e4c894a52137fa2c0e4aacb52c627247d7dc4f51b79eb1b03d1e5cb8ed83b940
SHA1 hash: e46b62d7bd65fced8f1ac14138f4c8fc7bbf2060
MD5 hash: 591ae464ba7d4cc002f35f4cfd5042ff
humanhash: florida-comet-snake-crazy
File name:090000900000000000.IMG
Download: download sample
Signature AgentTesla
File size:323'036 bytes
First seen:2020-07-13 06:21:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ev6pZxGVRax7KsYjKRiAbwhKMNXL1z8OeblTNKABkbl+1uhuWL8ON5R9eafKQzJO:CSx1whKghz8Oebfag1iH5R9+QFzOB/5
TLSH 2E6423698E20BFF78C32893736C27917962ED383D40AF1DD0976A6358B5BD510781BE8
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: h3.plesklogin.net
Sending IP: 208.67.23.101
From: finance dsw <finance@dutasegarawisesa.com>
Reply-To: saleslink@yandex.com
Subject: Proof of payment / New order
Attachment: 090000900000000000.IMG (contains "090000900000000000.exe")

AgentTesla SMTP exfil server:
mail.petekyazilim.com:587

AgentTesla SMTP exfil email address:
mustafaozturk@petekyazilim.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-13 06:23:04 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip ac309a343529c9ad2729aaf77975aade30b1a3e2e4d7360ed6cc054f17ddef58

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments