MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8493704bd4bfba80e23b626fa5a64846ddb2f6b3072d330826bb3c7072247ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b8493704bd4bfba80e23b626fa5a64846ddb2f6b3072d330826bb3c7072247ae
SHA3-384 hash: 54cce17aad67b59de983e2d46eef755c1a3656e2eeffd9991e596a14136b2abcdbae4a60e7835ecd211192d68a157a70
SHA1 hash: 8b68667673c75f20ee525454fb32ae2defead242
MD5 hash: 503c6ce70433d9fe1668f388c39c07b8
humanhash: island-yellow-georgia-fruit
File name:MA20-002423.zip
Download: download sample
Signature AgentTesla
File size:827'431 bytes
First seen:2020-05-11 14:38:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:xJHzs/+ircoSd4jPDYKQkkceb9sEiVqMwY8spTBWuqpcrA1hrHMWifHiM8FSgwtO:xJHo/iijLpkEYY8KQuqpmA4fHiMztF0
TLSH 1205330A569DB30F8170CDA4EB80763A37097295ECD46DDDBEF1AE3314AAD8A4D061DC
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Vladimir Djurovic <info@biokorntackt.com>
Subject: new offer
Attachment: MA20-002423.zip (contains "MA20-002423 WinterTrade Zrt Szeged Hungary.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 20:22:10 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b8493704bd4bfba80e23b626fa5a64846ddb2f6b3072d330826bb3c7072247ae

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments