MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb34e067d7441ce98d72b19e0674af5886791c3243ca96d1708c710e2a17a788. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fb34e067d7441ce98d72b19e0674af5886791c3243ca96d1708c710e2a17a788
SHA3-384 hash: b497f4a0d22f8557783ddefc7a208147653f827249324aaf1526a8a0f417ddb5702c1547728a4ffd5643c0b43ebddb0d
SHA1 hash: 6f57a6a6bc0636712b5f8cef364cef721a4be4f8
MD5 hash: 13aafa3b6f93fe242b8b84551139b5bf
humanhash: cup-golf-carbon-monkey
File name:purchase order.cab
Download: download sample
Signature AgentTesla
File size:407'003 bytes
First seen:2020-06-04 06:30:44 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:fmiQGXUsRSz0EXN474XK1IhViAtVbpkVJpNTvEHIA:fmfcAXO74XKKViA9mJvEHIA
TLSH 488423FF79BD498D8B0E9453C71C5687C81BAC97690C80ADBE19CD0984B837D82D6C3A
Reporter abuse_ch
Tags:AgentTesla cab HostGator


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gateway22.websitewelcome.com
Sending IP: 192.185.47.144
From: ventas@opelogic.pe
Subject: PURCHASE ORDER
Attachment: purchase order.cab (contains "purchase order.exe")

AgentTesla SMTP exfil server:
smtp.capeqlc.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 06:38:06 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab fb34e067d7441ce98d72b19e0674af5886791c3243ca96d1708c710e2a17a788

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments