MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a06cd2968ea44bdc4e3ceb54a9226a98e52cce51f73c0462f03820617aa29ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2a06cd2968ea44bdc4e3ceb54a9226a98e52cce51f73c0462f03820617aa29ac
SHA3-384 hash: 7b2adde6e390b00bdfc0c0c6406cfcd14f7cff5588f6988a85310b3cf26c576c815c0c6b82a93ad3c6a5923731422bd9
SHA1 hash: 4b1a1a6d392c467d7d79993260578feb51c9e04f
MD5 hash: 8d25013767944a03f7cc3f886bcb740b
humanhash: princess-asparagus-carbon-mockingbird
File name:COVID-19 ANTIBODY TEST PDF____________________________________________________________647463.gz
Download: download sample
Signature AgentTesla
File size:331'913 bytes
First seen:2020-04-05 08:58:46 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:NXUktMGpn+1nGavmi2L+YSVHcowYt8Psxn3wkAwlKvZDAlh/ceWFEf:Vjn+1nLvP2LrqcolZ6wlyArvgEf
TLSH 7864237A1ED0A0DBCB817DE8CDCB0F4F7115CA90E1290B9D29242759BB3BE1D22472D2
Reporter abuse_ch
Tags:AgentTesla COVID-19 gz


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: server.clinicasom.com
From: sales Trading LLC <soporte@clinicasom.com>
Subject: Re: COVID-19 tests CF&FDA Certificate
Attachment: COVID-19 ANTIBODY TEST PDF____________________________________________________________647463.gz (contains "COVID-19 ANTIBODY TEST PDF____________________________________________________________647463.exe")


AgentTesla SMTP exfil server:
smtp.epaindemgroup.com:587 (208.91.199.224)

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-05 09:35:46 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
21 of 47 (44.68%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 2a06cd2968ea44bdc4e3ceb54a9226a98e52cce51f73c0462f03820617aa29ac

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments