MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 faed71542fef99f47b0273b6727d49bc3c34d791d573fe5263828a8dcf4c6168. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: faed71542fef99f47b0273b6727d49bc3c34d791d573fe5263828a8dcf4c6168
SHA3-384 hash: a9553aac3b3c30336522f6398e81db399df9f63fce485198d09299d08791ea9404bece8b3da98e41072555eb24e370ba
SHA1 hash: 22a2076af6ff5718bd8a680cc4410c191fe28676
MD5 hash: 8979f43aa7eec7f44bb5d617d5d8e524
humanhash: november-fish-fillet-juliet
File name:Shipment Number - 6183111.zip
Download: download sample
Signature AgentTesla
File size:334'631 bytes
First seen:2020-07-11 06:24:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:d11ibVTAzPzUr5k38qkxLbdhbYDlu4oK9TDPphgCaYFTarQy3cFNhQA+6KKV:dIFQw5HqkpcDluiTjEgNlMPAFzV
TLSH 5064237F6AB6467742E3932BA9FA34CC27D59719D64F22DC0640A9C8F11A4FAA333510
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: madison.co.uk
Sending IP: 103.99.1.173
From: Customercare <customercare@madison.co.uk>
Subject: Shipment Number / Consignment  -  6183111
Attachment: Shipment Number - 6183111.zip (contains "Shipment Number -  6183111.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-11 06:26:08 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip faed71542fef99f47b0273b6727d49bc3c34d791d573fe5263828a8dcf4c6168

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments