MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fac5ea42ec11ef28ee619cebe246aa945662f501c23daf26f4f432b28b35dc3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fac5ea42ec11ef28ee619cebe246aa945662f501c23daf26f4f432b28b35dc3e
SHA3-384 hash: 3227d0dc708354918cde5f14867e7e3cbe212de37da89c035b8e72307545221a3259d642b0f54d440f79aeb8a396a431
SHA1 hash: 4b3fce0aa9fa14d1f06f1e4bac905226571fac33
MD5 hash: 25af27bd75a2cf0007a375c545363f70
humanhash: pasta-illinois-queen-tennis
File name:86597599579.GZ
Download: download sample
Signature AgentTesla
File size:488'866 bytes
First seen:2020-07-29 12:33:37 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:7iY6NvCh9rCb+fq9A+D8xOKVbmTY2VJIMNACqYaV:H64DrCEqO+4xrbmUgJTNACqxV
TLSH EBA42316737F653235510EA8B6808C4B5ABA5789F4F04E6D4F3ECD2B83B0069675FCA8
Reporter abuse_ch
Tags:AgentTesla gz Hostwinds


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hwsrv-755778.hostwindsdns.com
Sending IP: 104.168.234.182
From: "Emilia.Motoc"<Emilia.Motoc@sony.com>
Subject: RE:REQUEST FOR QUOTATION
Attachment: 86597599579.GZ (contains "86597599579.exe")

AgentTesla SMTP exfil server:
smtp.ionos.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 12:35:04 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz fac5ea42ec11ef28ee619cebe246aa945662f501c23daf26f4f432b28b35dc3e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments