MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cddab719c0126c26c1a74641ff4c279e68aa010ebd68442834f2b373e5425638. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cddab719c0126c26c1a74641ff4c279e68aa010ebd68442834f2b373e5425638
SHA3-384 hash: 20e415bba0636ee806f90ba2b8ccc0be17cf5326de5c719a2e0117e91b98af1109c41edbf700a80433c87387a21c5f54
SHA1 hash: a42a18a38b5be2bca03ea712e154bab35a941335
MD5 hash: 254ee6daa5bd2914f91d272e78cb0cb8
humanhash: carolina-johnny-lactose-south
File name:NEWORDER.rar
Download: download sample
Signature AgentTesla
File size:355'713 bytes
First seen:2020-05-20 11:10:53 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:1MFQS2nOHzZaAjHITdvc+ygimJ2R22vdpRatSDKzn6YKQY+OSrwgffyON32:GS9nOdTivcn1/d6SW2Yp0
TLSH 61742321529592D78D22578D0ED3AD93D90536DBBE192CA00B3E268AEBB3DE35F14C24
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: blank.cafe24.com
Sending IP: 175.126.38.143
From: Kyum Kim<kim@osc21.co.jp>
Reply-To: <abs0000100@gmail.com>
Subject: New Order Request
Attachment: NEWORDER.rar (contains "NEWORDER.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-16 00:25:53 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
15 of 30 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar cddab719c0126c26c1a74641ff4c279e68aa010ebd68442834f2b373e5425638

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments