MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf7a2a92da568615c512c1a53f0937242139002da39f3e51c94cd008f9a494c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: bf7a2a92da568615c512c1a53f0937242139002da39f3e51c94cd008f9a494c6
SHA3-384 hash: 7c076df3be97b910a9462e88feb682fb8fb2683f4439d53798b49a1cd3c4206678ba0ea5518b545564a39e90c7d8795a
SHA1 hash: 7825ee05c6d58c1143b77e23e3ea6f821fc3735b
MD5 hash: 9f81c744b74d9a3bb8ace9cac71ce7e6
humanhash: illinois-music-iowa-gee
File name:P.O 28602 21256 Hebei Ocean.zip
Download: download sample
Signature AgentTesla
File size:414'836 bytes
First seen:2020-05-22 07:24:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:xbmBisN5yayMZf+lFGfA2p2VBwDOjYLecJ:xKBNH8FD2p2MMY6+
TLSH 939423A89361EC5510627379444FCB23E6DA05CA5391D24D3293B438D85EBB37BB2E3D
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: jmlapparel.com
Sending IP: 45.11.19.32
From: Jenny Jiang <jenny@jmlapparel.com>
Subject: Amended P.O 28602 / 21256 Hebei Ocean
Attachment: P.O 28602 21256 Hebei Ocean.zip (contains "P.O 28602 21256 Hebei Ocean.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-22 07:36:51 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip bf7a2a92da568615c512c1a53f0937242139002da39f3e51c94cd008f9a494c6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments