MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e4499ec7dd7ff1fbb1cf6d578dc021b0df8fed5f31cce52c4f8fcca1635f374. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e4499ec7dd7ff1fbb1cf6d578dc021b0df8fed5f31cce52c4f8fcca1635f374
SHA3-384 hash: e506135bb44c1a48f65259c8c03ec624453139586c15617a56227e5d229106add3c7e8b51cf7d594e1385162fe042341
SHA1 hash: f8ca08e39443da9fe2da3fc63b198afd0d3cc338
MD5 hash: 8cee9169647e966fa9fca9d44c2be68e
humanhash: lake-echo-pasta-pennsylvania
File name:scan document.r01
Download: download sample
Signature AgentTesla
File size:688'519 bytes
First seen:2020-05-07 12:59:28 UTC
Last seen:Never
File type: r01
MIME type:application/x-rar
ssdeep 12288:J0lO3i9U0cx4tFkwfrReg+N651EcwI6O0IPPIuHaDm708b23lh6peXXJS1hcfkuY:J0lOgUvsSirYg+C1EcwIZBP1HaDY0E2S
TLSH 00E423E0AE337C5A4A07AE9590FD450E9C83160DECD3A92B082D9B71E0EC6EF5147977
Reporter abuse_ch
Tags:AgentTesla r01


Avatar
abuse_ch
Malspam distributing AgentTesla:

Sending IP: 185.164.32.55
From: Sajin M Thomas <purchase@yatfshun.com>
Subject: Kind Reminder-Urgent Inquire
Attachment: scan document.r01 (contains "scan document.exe")

AgentTesla FTP exfil server:
premium38.timeweb.ru:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-07 13:35:25 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r01 0e4499ec7dd7ff1fbb1cf6d578dc021b0df8fed5f31cce52c4f8fcca1635f374

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments