MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2537581d7fb21ca9583c34ae1e260df52658ec22dcb7650c6835c1239789a0e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2537581d7fb21ca9583c34ae1e260df52658ec22dcb7650c6835c1239789a0e1
SHA3-384 hash: 9a5cf67161a035d02f3cfdd6b2647c836c174435b040c7505e2857288fc170860bb68a50fccdc738686ba0d8d21c085d
SHA1 hash: e8daf2cf789f3b22887598b1cb9983093e253f5e
MD5 hash: e987bf2626bb3ec2b67cb51f7af40f90
humanhash: dakota-emma-potato-timing
File name:001100020098454_05-13-2020.7z
Download: download sample
Signature AgentTesla
File size:396'895 bytes
First seen:2020-05-13 06:54:56 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:yNEIgn13jLFQW5DFvAXux9/O8vt7aba/4z:bIi13dvIKpO8vt7Cagz
TLSH 798423EB71B5E14FEEE8427901C7B1DB00C8AF149101DBA055BA614FB4A1FBAB643F16
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: main.vmx.hu
Sending IP: 178.248.200.106
From: Octav Voiculescu <octavoiculescu2@gmail.com>
Subject: ultima plata
Attachment: 001100020098454_05-13-2020.7z (contains "001100020098454_05-13-2020.exe")

AgentTesla SMTP exfil server:
mail.elhelado.com.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 06:07:55 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 2537581d7fb21ca9583c34ae1e260df52658ec22dcb7650c6835c1239789a0e1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments