MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd27020b54d277e89e892f30aabdb646a649fb91bf6cc73f084f454c789eca7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bd27020b54d277e89e892f30aabdb646a649fb91bf6cc73f084f454c789eca7b
SHA3-384 hash: 40d1cdf996e911c44d1c397c1179e0951f065a6d3ce2b2c8c06c48bebc1cc2977eb2a3e04bc8d4673c8fc4c085c3dcdc
SHA1 hash: b0ca8f1e8222ac3ad0e673e5fdea1c36b0ab3637
MD5 hash: ddba98dffc5716a0bd2067c8f33a8ae4
humanhash: mike-violet-pennsylvania-bluebird
File name:PRODUCT LISTS.zip
Download: download sample
Signature AgentTesla
File size:395'272 bytes
First seen:2020-04-02 08:33:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:D2IH968CQbLUIk0SkRd918t64MJC5MKAm+YTxuQ0Og4nMowADPOv1b9CNbeZ8Mdo:JH968CQ04t91ID5PCKxUOj61ubeZbHI
TLSH D98423EA4C24B1BC410FCC68491E687EC9F11B679B99A4780BBD1D4522667C2CBE377C
Reporter abuse_ch
Tags:AgentTesla COVID-19 zip


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: linux1117.grserver.gr
Sending IP: 95.216.16.146
From: U.S. Department of Health & Human Services <Hubert@ushealthdep.com.us>
Subject: URGENT NEED: U.S. Department of Health & Human Services/COVID-19 Face\x0a Mask/ Forehead thermometers..
Attachment: PRODUCT LISTS.zip (contains "PRODUCT LISTS.exe")

AgentTesla SMTP exfil server:
smtp.bapipl.com:587 (208.91.199.225)

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-03 04:10:48 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
18 of 47 (38.30%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip bd27020b54d277e89e892f30aabdb646a649fb91bf6cc73f084f454c789eca7b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments