MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4c5fead3bc308faa465962c0e60d2cdf504f3592065cd3056d74052107a23d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b4c5fead3bc308faa465962c0e60d2cdf504f3592065cd3056d74052107a23d6
SHA3-384 hash: ca8b1e9d6272db76b18d863dfe10e67ca1150b8d782e022e41e355a946aa91e730199266eb5b5465793517e90e19fc65
SHA1 hash: 3d9ecca40da449e8692d2cea07a9fc2112191e84
MD5 hash: 1bef1d3d6e5b109dad0264727fa5b874
humanhash: cola-artist-twenty-aspen
File name:CargoINV.pdf.arj
Download: download sample
Signature AgentTesla
File size:496'483 bytes
First seen:2020-06-03 11:50:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:LrChMlJXqxX8gCzJVFagoW20D3GkJwmxrThfYFyflweRxzokoI:LrChy+8gCJnxoimGrNAMDzj
TLSH 5AB423B70C5E606F4EAD29FCD9985B770766E27306E316FE11A07809DD2256B3C8DC81
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: seatrans.co.in
Sending IP: 103.253.125.205
From: SB Hwang <weh1@j-walong.com>
Subject: RE: Additional BL[CArgo Arrival]
Attachment: CargoINV.pdf.arj (contains "CargoINVpdf.exe")

AgentTesla SMTP exfil server:
secure231.servconfig.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 11:09:16 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b4c5fead3bc308faa465962c0e60d2cdf504f3592065cd3056d74052107a23d6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments