MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb1f54e21f6ea9b8f752e5f80ef432599f730df73c2fe590d1c68d9a681b5bf6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cb1f54e21f6ea9b8f752e5f80ef432599f730df73c2fe590d1c68d9a681b5bf6
SHA3-384 hash: 2212ab6111922e0c372c954d696cd9d25f4f383e38ee45dba5472f7edd14792a70657b58882dba72086a0fdc95b7fd0d
SHA1 hash: 4a4a281d8093ea71678ff8193d30bae644800ed7
MD5 hash: f1d667b216d2539cef385bdea7ea4bed
humanhash: alanine-cold-kentucky-thirteen
File name:new order.zip
Download: download sample
Signature AgentTesla
File size:411'548 bytes
First seen:2020-06-04 12:47:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:WFBu84FuNj+degYan5hsCKrOK8NPvmSX5/bU2J5sm35ZGAPyiTjH:gBeeeyOXB9U2ImbraiTjH
TLSH A89423A166DD61153612F6F3204BD6C13D28AF879E9F380A7C5E0F7249688E2C71BF02
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vm16625.v-channel.com.my
Sending IP: 183.81.166.25
From: MS NAUTICA SERVICE <msnauticaservice@gmail.com>
Subject: New order
Attachment: new order.zip (contains "new order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 13:36:41 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip cb1f54e21f6ea9b8f752e5f80ef432599f730df73c2fe590d1c68d9a681b5bf6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments