MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ead8269b5ad5ea17a492ad9b551c6134244d45eec7197b90637d5ee17990e108. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | ead8269b5ad5ea17a492ad9b551c6134244d45eec7197b90637d5ee17990e108 |
|---|---|
| SHA3-384 hash: | cadfaad913b4f7ba9239d10a84a7ed6d5a82630f06204c8b86ac2d3c3c270485828090a8f15946384ad4cb4902244f42 |
| SHA1 hash: | 885a2f73ace94059c9406edcf874d859fb6576b4 |
| MD5 hash: | 7f120472ad6026988041742236b1f052 |
| humanhash: | yellow-burger-winter-october |
| File name: | PO 12ARG24072020.xz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 354'252 bytes |
| First seen: | 2020-07-24 13:33:45 UTC |
| Last seen: | Never |
| File type: | xz |
| MIME type: | application/x-rar |
| ssdeep | 6144:+Y4qBK4yH93OoryuReoyAhsfqKQxrmXKLb+94uxrcjXw8mjwYtwu6xvryMNjpRDW:+iBfy0oOuRTYyrEKLbo4uN4XwVcYtYju |
| TLSH | 807423EA3925587882F6D09A7A1CC2344B4E37487603DDFD7DDE2E3069B21A4792F930 |
| Reporter | |
| Tags: | AgentTesla xz |
abuse_ch
Malspam distributing AgentTesla:HELO: cloudhost-741824.us-west-1.nxcli.net
Sending IP: 173.249.144.125
From: Elena <info@excellaglobal.com>
Subject: PO#12ARG24072020-URGENTE
Attachment: PO 12ARG24072020.xz (contains "PO# 12ARG24072020,DOC.scr")
AgentTesla SMTP exfil server:
smtp.privateemail.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-24 13:35:04 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.97
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.