MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f506bed39ef88d088f9b0646c8ff357be10c59ea326f9ce7b9c031b9d0a5a254. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f506bed39ef88d088f9b0646c8ff357be10c59ea326f9ce7b9c031b9d0a5a254
SHA3-384 hash: e40f7f9b58bafcb5135fae848e7e474e0c7fb17946a40d563f6b43ed23dfe8439ce8b843aa4f65e1bb0fcf599ad5026b
SHA1 hash: 95eb523cc2c7b54e9d68dfaab8a05aeabd052886
MD5 hash: 81f362d5214097da678a764b4076bdf2
humanhash: louisiana-crazy-leopard-king
File name:RFQ LM2936MPX.IMG
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2020-08-04 07:49:20 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:HHcPgYxmOE+2Do4pPeRH89frMKA9AeV5JvK7lqtXcyTJgDzUBeaVDV:cIYxPeVZlpMKAdJsqtfKDyV
TLSH E965AFC2F5488E54EC194A3A483359924B33AD6BEF02460634DCFA5D6BF31966A35FC3
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hwhk-220-21.mailset.cn
Sending IP: 36.255.220.21
From: 廖桂英 <sanmi@hrb-dg.com>
Subject: 订单 LM2936MPX
Attachment: RFQ LM2936MPX.IMG (contains "RFQ LM2936MPX.exe")

AgentTesla SMTP exfil server:
mail.kimberleygroupbd.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-04 07:51:06 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img f506bed39ef88d088f9b0646c8ff357be10c59ea326f9ce7b9c031b9d0a5a254

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments