MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 251cce6f57ca5e0faf21c3c99b9a12ec39948d5bb94c2ddc08ad91e56be5cf3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 251cce6f57ca5e0faf21c3c99b9a12ec39948d5bb94c2ddc08ad91e56be5cf3c
SHA3-384 hash: 54a95a274f350e8e260e01cb081fd2fe44e74216848308f763d04f25eb1c01edf712670aadbffd65d00bfe2ff935f941
SHA1 hash: 892fffd972d8f49a7869d1f0e806c920d255fafc
MD5 hash: f7716e06649d4c514f42cb4d1f07ffac
humanhash: glucose-lithium-magazine-paris
File name:Purchase order.zip
Download: download sample
Signature AgentTesla
File size:619'036 bytes
First seen:2020-08-03 13:44:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:2pP/KbagPqCXg6a7dwDKGtxccG/jKqkt5CVftvrAtIEtpmrb:cPCbagyCXPa7d7GJGbKqkLCVFjAtxTmX
TLSH EFD4336155C6266584E9CA7B3121C0D8F0F44DBFCB4E6599E5E5B2D0C8CB24F1ACB6C3
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chingcheng.com.tw
Sending IP: 209.58.144.239
From: daniel@chingcheng.com.tw
Subject: RE: Official purchase order (PO.4029530)
Attachment: Purchase order.zip (contains "Purchase order.exe")

AgentTesla SMTP exfil server:
mail.multitec-bo.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 13:46:12 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 251cce6f57ca5e0faf21c3c99b9a12ec39948d5bb94c2ddc08ad91e56be5cf3c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments