MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da3925dc66dc3da2379b302fa07ba41636b2fdb501b13d0b9300e8eb61df6c1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: da3925dc66dc3da2379b302fa07ba41636b2fdb501b13d0b9300e8eb61df6c1f
SHA3-384 hash: 7f7bfbe2ccebd96f57823c800a7065ab022d096b04bc02ed66f5375d97bec2a18a2331dceb03031fb59c1a5586a884a8
SHA1 hash: aabab0010212663315a5794c068d6c38421db0f9
MD5 hash: 85b44b67be9a0065adbb83b00f4af24e
humanhash: enemy-ten-florida-high
File name:DOC051320-05132020073711.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-27 08:51:15 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:E+3U+4bcZdQoTzb+X3rDFNBRyAiJM16wHv/AIi8j:X3U5bydPLGZs
TLSH BA45CF8D721076EEC867D4B68A542C64AB602C77431BD247A91B30DA9F7DAC7CF244E3
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: bubiyanshipping.com
Sending IP: 209.58.149.67
From: Info <sujith@bubiyanshipping.com>
Subject: Re: LUJJAIN// FOB SEA//RE: SHIPMENT 20 F. Full Container shipment//50SPAPR20 ///BISCOSP1289
Attachment: DOC051320-05132020073711.IMG (contains "DOC051320-05132020073711.exe")

AgentTesla SMTP exfil server:
smtp.jpme.org.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-27 09:12:48 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
13 of 30 (43.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img da3925dc66dc3da2379b302fa07ba41636b2fdb501b13d0b9300e8eb61df6c1f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments