MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f506bed39ef88d088f9b0646c8ff357be10c59ea326f9ce7b9c031b9d0a5a254. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | f506bed39ef88d088f9b0646c8ff357be10c59ea326f9ce7b9c031b9d0a5a254 |
|---|---|
| SHA3-384 hash: | e40f7f9b58bafcb5135fae848e7e474e0c7fb17946a40d563f6b43ed23dfe8439ce8b843aa4f65e1bb0fcf599ad5026b |
| SHA1 hash: | 95eb523cc2c7b54e9d68dfaab8a05aeabd052886 |
| MD5 hash: | 81f362d5214097da678a764b4076bdf2 |
| humanhash: | louisiana-crazy-leopard-king |
| File name: | RFQ LM2936MPX.IMG |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'441'792 bytes |
| First seen: | 2020-08-04 07:49:20 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:HHcPgYxmOE+2Do4pPeRH89frMKA9AeV5JvK7lqtXcyTJgDzUBeaVDV:cIYxPeVZlpMKAdJsqtfKDyV |
| TLSH | E965AFC2F5488E54EC194A3A483359924B33AD6BEF02460634DCFA5D6BF31966A35FC3 |
| Reporter | |
| Tags: | AgentTesla img |
abuse_ch
Malspam distributing AgentTesla:HELO: hwhk-220-21.mailset.cn
Sending IP: 36.255.220.21
From: 廖桂英 <sanmi@hrb-dg.com>
Subject: 订单 LM2936MPX
Attachment: RFQ LM2936MPX.IMG (contains "RFQ LM2936MPX.exe")
AgentTesla SMTP exfil server:
mail.kimberleygroupbd.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-04 07:51:06 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.87
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.