MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2909e9a7f4e544cb4089a7f05e3af83c1d6faeb5d3c0d82c0938cd369cba8d8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2909e9a7f4e544cb4089a7f05e3af83c1d6faeb5d3c0d82c0938cd369cba8d8f
SHA3-384 hash: fb8d9b8b63411f0f09352bf4e1c377328d58f1d867019424e9ab8e1a6fd00acac573efcc1f0da926ed0856d31e03ac69
SHA1 hash: b15f2cd0590d755c5f8cc11b0142ca11908d4afa
MD5 hash: 8448a2b6396013f5d31af44da4a324f8
humanhash: virginia-emma-missouri-video
File name:Fwd WRONG BANK DETAILS.zip
Download: download sample
Signature AgentTesla
File size:400'333 bytes
First seen:2020-08-17 06:33:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:kgnPtmegUVTfkqxBgIgbPmZze2Oh9EbHBR:kYnkMmbrz3GBR
TLSH F984230A517190B8BB1E1F00F99BED587932998D48E04F16B25BDD09F4EBFA63B08B15
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cpshared8.tedata.net
Sending IP: 213.158.180.204
From: a/c <kris.brumley@contentstreams.com>
Subject: Fwd: WRONG BANK DETAIL'S
Attachment: Fwd WRONG BANK DETAILS.zip (contains "Fwd WRONG BANK DETAIL'S.exe")

AgentTesla SMTP exfil server:
mail.opporajasthan.in:26

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-17 03:30:39 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2909e9a7f4e544cb4089a7f05e3af83c1d6faeb5d3c0d82c0938cd369cba8d8f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments