MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13958f0178772fcf216e561e0be5b67d4e447ef96a4bfa3860244e0791e9eca8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 13958f0178772fcf216e561e0be5b67d4e447ef96a4bfa3860244e0791e9eca8
SHA3-384 hash: 0adbc460d144fe3ebf2f5efc0649d36c5e60cd3ed47989c06ebb97b801c8445dd5dccd7f0e2fbb4448b3ed9a77e9e0b1
SHA1 hash: 1878f0e9d74a53527e7ddfc68b8eadd985cd893a
MD5 hash: 44930bf26f3626fb0595e31a3bf44569
humanhash: uniform-carpet-jupiter-delaware
File name:Consulta de compra RE Factura proforma.arj
Download: download sample
Signature AgentTesla
File size:596'410 bytes
First seen:2020-06-02 19:12:07 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:K4VnZjow2P+KfKFgNuh6etbvHNbtxVEhVG3iVmE3Hk+LVh4x5:Kitow2khXHzv8U3iVmWxLVh0
TLSH A5C423C1F82EA46F7CE22BC93410E738DBAA59B851A104F5BC4674C4F7B96D08E81796
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: park-mx.above.com
Sending IP: 103.224.212.34
From: Iporras <aramos@districomp.com>
Subject: Consulta de compra: RE: Factura proforma
Attachment: Consulta de compra RE Factura proforma.arj (contains "Consulta de compra RE Factura proforma.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-02 00:23:55 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
16 of 47 (34.04%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 13958f0178772fcf216e561e0be5b67d4e447ef96a4bfa3860244e0791e9eca8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments