MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03a6bdfcdb3a909028488f9fd7e65f508bbe6f9aee214570030260ed3a2ab0d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 03a6bdfcdb3a909028488f9fd7e65f508bbe6f9aee214570030260ed3a2ab0d0
SHA3-384 hash: df809b5fffe5d18f31295332459ad703c3c67983b3c9d682490354c8dbb8765ee240ee406100e661af4e1a071813f753
SHA1 hash: fa17b7262f097ec0006a9dfd3af303f275d2900a
MD5 hash: 23f11cad0cdf49ea3fcefde0071f229d
humanhash: angel-foxtrot-edward-yankee
File name:PO no.0107-320804-1.arj
Download: download sample
Signature AgentTesla
File size:293'746 bytes
First seen:2020-08-17 06:02:45 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:JxbVgOBks1hgTz1vPRLqMuzuEGAEsRkWclNSTIC4Eni:/BEs1KT1RLqDnCslclcEUi
TLSH 4554239868C775A3C98E9AD62DD3F6115ECF300BE37B68F416A2F0821087207DD65BA5
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: squadraperu.com
Sending IP: 23.106.223.168
From: Larry Berkemeier <margaravega@squadraperu.com>
Subject: URGENT REQUEST FOR QUOTE// Ref: PO no. 0107-3/20/804-1
Attachment: PO no.0107-320804-1.arj (contains "PO no.0107-320804-1.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-17 06:04:06 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 03a6bdfcdb3a909028488f9fd7e65f508bbe6f9aee214570030260ed3a2ab0d0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments