MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aece87c524b8edd5af789c8aab3ed730fcd982b0bcc815c36fb632c951ba51c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: aece87c524b8edd5af789c8aab3ed730fcd982b0bcc815c36fb632c951ba51c4
SHA3-384 hash: 86c262709d0528a134cb6c83484c1154314143d30f76e148acab4754cee00d1c438fa83a2717fed51b64750affda154e
SHA1 hash: deebcad210ca0dee12106807987872b5c99483a7
MD5 hash: 6b1b92bc5ff6aab7ae49bd1051eb02c0
humanhash: massachusetts-princess-quebec-helium
File name:purchase order with drawings.r00
Download: download sample
Signature AgentTesla
File size:551'915 bytes
First seen:2020-08-03 13:19:59 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:GpGPupMwq65IkflFHF8aesBBvRgVqwzKsVulM/op+HyQjhIQ7X:sGBwq65IgQwvMqqdVuaQujyQ7X
TLSH 4FC42343478056CE73E0A642F686A7892ECFD2416AEF77ED70FD903ED02168CC85B656
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hosting105.serverhs.org
Sending IP: 194.39.124.63
From: fernandof@frontfuels.pt
Subject: Order in Request for price information
Attachment: purchase order with drawings.r00 (contains "purchase order with drawings.exe")

AgentTesla SMTP exfil server:
mail.totallyanonymous.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 13:21:05 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 aece87c524b8edd5af789c8aab3ed730fcd982b0bcc815c36fb632c951ba51c4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments