MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f93a549b02a7e5e2c69447f9e80be87dcee4d4768b6c857438a244d67069669d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f93a549b02a7e5e2c69447f9e80be87dcee4d4768b6c857438a244d67069669d
SHA3-384 hash: 47e1cc5920ed8b4668558dbab3c728ed3ffdc3a7361fe79cf17ed02008dc2fb4bd0a5e32243b1c7cd963883dad925682
SHA1 hash: b80530a0c2d41db93565eb11c917fbcdb1f69c0b
MD5 hash: d06805215fb9d61ec7f0cd79e5914955
humanhash: pennsylvania-nevada-north-vegan
File name:Document Copy.gz
Download: download sample
Signature AgentTesla
File size:278'039 bytes
First seen:2020-05-20 07:12:32 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:u40hWC8D5zUMJ0DHTOEWqaB2Rd53cSXs0MiqumsLjkaLQ0CbiegS:uNhr81zU97yEWqaB2z53cSc0xqE37pW
TLSH 0B4423CE1992D13723F89F4F1476A85B496725BD034436CCF261DE3282F46E6B98A1B3
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ficci.com
Sending IP: 217.61.107.95
From: Regards, Dilip Chenoy<dilip.chenoy@ficci.com>
Subject: Bain & Company's latest insights on the impact of COVID-19
Attachment: Document Copy.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
mail.flood-protection.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-20 06:49:58 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz f93a549b02a7e5e2c69447f9e80be87dcee4d4768b6c857438a244d67069669d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments