MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27e1ae7639a58a54ce8ee5baf13d60581a06434d864315203165deb0e04a3d1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 27e1ae7639a58a54ce8ee5baf13d60581a06434d864315203165deb0e04a3d1f
SHA3-384 hash: ef0bd6e56c81841dcbeaedbd7de432b33a9ae5452d7b1c921c22c909ce5d91394433e42ce2ae1447f5fb40891f5908e6
SHA1 hash: 48a3a024c111e4335a0fcc685a08f63b404e5b41
MD5 hash: 15c7de52d8c00582be35201bbae631da
humanhash: helium-venus-twelve-potato
File name:Reconfirm Swift Code.pdf.r03
Download: download sample
Signature AgentTesla
File size:562'308 bytes
First seen:2020-08-04 06:10:53 UTC
Last seen:Never
File type: r03
MIME type:application/x-rar
ssdeep 12288:av2E38xvYdbIAzQyH7n4nizJYB8a0GneK:Px0bv4nizaBn3
TLSH C4C42321D5C4E53C122D842FD98184B6EEB3AA6C7E3E3FD949B794E1F36254E8387604
Reporter abuse_ch
Tags:AgentTesla r03


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.thebricspost.com
Sending IP: 64.15.138.14
From: ACCOUNTING <info@semco-ltd.com>
Subject: FWD: Reconfirm Swift Code
Attachment: Reconfirm Swift Code.pdf.r03 (contains "Reconfirm Swift Code.pdf.exe")

AgentTesla SMTP exfil server:
smtp.coffiices.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-04 06:12:08 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r03 27e1ae7639a58a54ce8ee5baf13d60581a06434d864315203165deb0e04a3d1f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments