MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0ae8b977f7534f88b032e60a9568ee32dd0431de006a71c1018a688cd20b7e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c0ae8b977f7534f88b032e60a9568ee32dd0431de006a71c1018a688cd20b7e7
SHA3-384 hash: d73863150d17a0e8c58af9d1cd5e52896d43cda7f4c8f4e44fb523fd3b17ef8c82dea4ad33e08a24fe1409eadf3be4aa
SHA1 hash: 5b40a07dde210ee22e3e4d5a73348d4734357cc7
MD5 hash: fea80c0e496f4543133a61e93f094885
humanhash: purple-glucose-zebra-nine
File name:Invoice.8966.scan.rar
Download: download sample
Signature AgentTesla
File size:245'494 bytes
First seen:2020-04-30 11:34:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:zugmOV74H9ahvlS1cjXDg0SQKsGB7UxJdISMs1j9wr8PwEFTruR:zJVsHWvlVXDg0Cf7W/I+d9JoiTiR
TLSH 0534225ED4D7034526ECCE74AFF35FA2B782194BACE760D2166DF1ADEB98D2E0044620
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: droid.superhosting.bg
Sending IP: 195.191.149.12
From: dualszky kovacs <info@drlenti.com>
Subject: Payment Swift Copy *3rd Party Remittance
Attachment: Invoice.8966.scan.rar (contains "Invoice.8966.scan..exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-30 11:37:03 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c0ae8b977f7534f88b032e60a9568ee32dd0431de006a71c1018a688cd20b7e7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments