MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d2c9313b515c94be6ccc45c5d35414d3dc82a524c8353cdb89897c94999ccf93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d2c9313b515c94be6ccc45c5d35414d3dc82a524c8353cdb89897c94999ccf93
SHA3-384 hash: 8a4af73ba016851c1570e769af7956bd50399e1a9c462973bb3502bc64297f25ab60927e74bad6b336f5215f23f52da7
SHA1 hash: cb581f4c96afb0880cc1c8d9b3c6c35c4cabfa15
MD5 hash: 05e014a34a1d786128de4a05ea553479
humanhash: early-hydrogen-sierra-pluto
File name:Doc-files_receipts.arj
Download: download sample
Signature AgentTesla
File size:418'802 bytes
First seen:2020-04-30 07:49:20 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:waXtCKR8g1CpommYJRSBnIm4hZn5nHrrfx3eN2BLK43v+QZ:wa3O/SBnFmfH53Lmmb
TLSH 6B94239E88308DE797B0C4647D50A7519BF8586A3345B3C73F6D24B068EF293A2588DC
Reporter abuse_ch
Tags:AgentTesla arj DHL


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.ofismedya.com
Sending IP: 89.252.177.223
From: info@athenaparfum.com.tr
Subject: Fwd: DHL Shipment Successful ::Air Waybill no 12616*****
Attachment: Doc-files_receipts.arj (contains "Doc-files_receipts.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-30 08:36:13 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj d2c9313b515c94be6ccc45c5d35414d3dc82a524c8353cdb89897c94999ccf93

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments