MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ccda67513234cbe9082a230bad61a07ae428a1e0cb2e132777ff5895fa2ed642. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ccda67513234cbe9082a230bad61a07ae428a1e0cb2e132777ff5895fa2ed642
SHA3-384 hash: 03b0bc6ffb994a0d2e31ec32fc8f2c3eb1ff4dd9acc739e4fb07d1c572ef91aca1735788af19b52492645e31ad95d319
SHA1 hash: 2f56b209c9e1d0ac6ddd0fb2d9dc6d788dcb3bf2
MD5 hash: 87b1c5fdb501ddf7fd5dfd3a311a44be
humanhash: alpha-burger-helium-angel
File name:Proforma Invoice - PI.rar
Download: download sample
Signature AgentTesla
File size:610'523 bytes
First seen:2020-06-03 08:41:21 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:dheYF3OhDGNNtQulXpfHjYuNAm7QbLqfwRI79KIJr35O211hPUaZcWTVuP8:GzVGNBXfHjQm7QTRI7QIZce1xFZhu8
TLSH D3D42328143262FFA9D380246BDBF5853DBD4951405B724C8892D1ECB29F60FBEA75F1
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: qq.com
Sending IP: 183.3.255.89
From: sales@heroim.com <sales@heroim.com>
Subject: Proforma Invoice - PI
Attachment: Proforma Invoice - PI.rar (contains "Proforma Invoice - PI.exe")

AgentTesla SMTP exfil server:
samiprinting.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 04:29:30 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar ccda67513234cbe9082a230bad61a07ae428a1e0cb2e132777ff5895fa2ed642

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments