MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ccce2dc0a5a07dcd0cc1f9b7bf8405f55aca44798d8c3e3dfb11f9f312974670. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ccce2dc0a5a07dcd0cc1f9b7bf8405f55aca44798d8c3e3dfb11f9f312974670
SHA3-384 hash: e6b5b59874001d8c8ded9b3df258214711c46bd745b5d7a920a4382f74349ed5449d8c72f2ff338e913490cd1a7421ba
SHA1 hash: 3bf1df4aac4772ea4fefacfb1f81fc763bea4237
MD5 hash: 5160f5c23b2d38d048f710d568b6da60
humanhash: harry-fix-pip-georgia
File name:Wagon Group Order 20200601.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-02 08:22:30 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:rMMMRIaj+N0T+tqdasueNWSLTNPad5Th5fNZx7jbQP1wnTLl2:rMTrj+N0ayPvLTNPE5ThN
TLSH 96456C66236062EDFB72B4F29D1C2E20D534DDFF8985B80D6723396B562C062E637079
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: groupwagon.com
Sending IP: 103.133.105.20
From: "Wei Meng" <weimeng.hkg@groupwagon.com>
Subject: FWD: New Order List
Attachment: Wagon Group Order 20200601.img (contains "Wagon Group Order #20200601 ,jpg.exe")

AgentTesla SMTP exfil server:
mail.ilclaw.com.ph:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-02 08:36:40 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img ccce2dc0a5a07dcd0cc1f9b7bf8405f55aca44798d8c3e3dfb11f9f312974670

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments