MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12fdc7b06c9e59462a5eb0f21a0e7764683e833b85ecc2d8ec5afb630d77eb57. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 12fdc7b06c9e59462a5eb0f21a0e7764683e833b85ecc2d8ec5afb630d77eb57
SHA3-384 hash: 7eba09439b92fe25b647d2f9ebf6e23676a204ab2d894bba74cad8d1d3e41d2408b4959b15664f93d71e8334dfa1dce4
SHA1 hash: 380ba8e748ebaa420adf735d891dc9858f4e2a0d
MD5 hash: 73db391d83ee0a2a6516bc4c729a0653
humanhash: lake-delaware-nitrogen-uranus
File name:72EKBF036H INV.rar
Download: download sample
Signature AgentTesla
File size:460'297 bytes
First seen:2020-06-02 10:31:41 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:66ddHAAwBLegoLwwer3y9amwFbX7pgyCSD5Z:P2w3Lw7ravyX7pFZ
TLSH EBA4230B001A2C285E76DE9A6F078DD5973A17B8603F9E1D310EA429720E6357F291FF
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: linux937.grserver.gr
Sending IP: 94.130.200.165
From: pkkolias@kkolias.com
Subject: Re:No.72EKBF036H INV
Attachment: 72EKBF036H INV.rar (contains "72EKBF036H INV.exe")

AgentTesla SMTP exfil server:
smtp.epaindemgroup.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-02 10:36:52 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 12fdc7b06c9e59462a5eb0f21a0e7764683e833b85ecc2d8ec5afb630d77eb57

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments