MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc1e450efec9b45b3810642bcfdb4c0104fd7e26f7f4087f725156133af0fcfe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fc1e450efec9b45b3810642bcfdb4c0104fd7e26f7f4087f725156133af0fcfe
SHA3-384 hash: 5f373dbe976041612a428413321a61ff5d437fe40f918d532c43825b3636fd540f1c489baccd40034db26c72c96f427f
SHA1 hash: fa25dd9419802931095560fce0c1eb2847910541
MD5 hash: cd2a633329d10ff492356be86e11cb4e
humanhash: kilo-emma-stream-pennsylvania
File name:bergebulk PO no 01172320202505.zip
Download: download sample
Signature AgentTesla
File size:391'041 bytes
First seen:2020-06-15 14:00:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:HGGynsNHglTkyZBAsv9IsCBx+E4PWjbyILm/m8FYzC37kiTuCpOpUS98TwoedWU7:HhysNHgl2sv9ZCBx+E4uny08eWLVubUq
TLSH 218423E4A9D92E7F96212EFF8FD71378D0109B995CA0263A7020FB62FD7E472551A013
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kvit.in
Sending IP: 101.53.143.139
From: tingxuan.teo@bergebulk.com
Subject: PURCHASE ORDER No: 01172320202505
Attachment: bergebulk PO no 01172320202505.zip (contains "bergebulk PO no 01172320202505.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-15 14:02:05 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip fc1e450efec9b45b3810642bcfdb4c0104fd7e26f7f4087f725156133af0fcfe

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments