MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e29954c7b3c9051d746566c4e07a27b6eca24584735f266fb0e656b8c952e628. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e29954c7b3c9051d746566c4e07a27b6eca24584735f266fb0e656b8c952e628
SHA3-384 hash: 28c624d1d0768bcca7a517a2cc8ad51ede5ead75e54d471467983c10efdb80ad6f9a3df7cc181270357a5d01fb45afa6
SHA1 hash: 4657000573ae942bdaced2f12e784b9e60432637
MD5 hash: 2e73a99de16736c57e54d18a479e403d
humanhash: mike-red-vegan-victor
File name:PO64646_NEW89.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-09 07:22:14 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:tDJyCixkGE6JEe7Qw4KXKis4XS3tJqC3PYgr:BidE6z8w4KaiU
TLSH 6845DF04795D22AED01B8A754993A864C755F5733242D366A88B1E89FFFDF80CEC2C72
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mx.zmail.biz.id
Sending IP: 103.66.86.83
From: WHO Payment <andy.gui@toplinkind.com.hk>
Reply-To: info@tountasmarine.gr <infojanboy@yandex.ru>
Subject: CONFIRMER LA COPIE DE PAIEMENT
Attachment: PO64646_NEW89.IMG (contains "PO64646_NEW89.exe")

AgentTesla C2:
http://193.169.52.158/image/inc/4ec2ddce4ea332.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-09 07:35:52 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img e29954c7b3c9051d746566c4e07a27b6eca24584735f266fb0e656b8c952e628

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments