MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdfda4547f85e0d0bec8c33017f3518ecb9ecbb0989b5b6b9100676f8351db0a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fdfda4547f85e0d0bec8c33017f3518ecb9ecbb0989b5b6b9100676f8351db0a
SHA3-384 hash: b787de67610ea8d18e94b930c38103a6326c41115526a03e73e3737ffca5f3bb7d3f85121d31dee3a9b91f38e6c8b1c8
SHA1 hash: ecde1ed8c4eafd81c3ca7d3f99d84df9afe3f94e
MD5 hash: 31a7054988d0654aa8a72e0893804aed
humanhash: edward-sad-butter-nevada
File name:Booking Ref1 DF000083-JJ.cab
Download: download sample
Signature AgentTesla
File size:727'019 bytes
First seen:2020-06-02 12:05:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:bxy49/xy+Rvq8l0DbOwWJzh/jrkqMZtZL60yHLWW5tDqGe6of+z76Rm:bxr9/BvqyCbjQzN/qMlTDLzv
TLSH 2AF42324B4C3211BA54136BC11379A3AD63B2E5296DAB5A7394613F8443D63CEABD3CC
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: apollo.t.mk
Sending IP: 195.26.152.35
From: atri@t.mk <atri@t.mk>
Subject: BOOKING
Attachment: Booking Ref1 DF000083-JJ.cab (contains "Booking (Ref1 DF000083-JJ).exe")

AgentTesla SMTP exfil server:
mail.radiomeff.mk:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-02 12:37:38 UTC
AV detection:
15 of 47 (31.91%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar fdfda4547f85e0d0bec8c33017f3518ecb9ecbb0989b5b6b9100676f8351db0a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments