MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ea8c7567acb553dad1fb980204cecaad869fea7d5e3eedf214b3c4bd1fb6349. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2ea8c7567acb553dad1fb980204cecaad869fea7d5e3eedf214b3c4bd1fb6349
SHA3-384 hash: 6b364212433bb63478e00dc5274711da07c4759b1e6b2e207f968021653e0b7c8adb35ce9382044d9c0acceaf9635043
SHA1 hash: f1cf643660cabc9159b3e13f724ede746d0bb1d2
MD5 hash: 5ed092352a6bfc93fc08f059444867b9
humanhash: solar-october-violet-butter
File name:Nasco Emirates WLL - 27052020.gz
Download: download sample
Signature AgentTesla
File size:388'162 bytes
First seen:2020-05-27 10:03:51 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:g9b0ExuYQ2hwyAcmNA9gbBfQz+FkS9t110SCkShw7rUJ4kLr0PRU4qpK8ws3U1kl:mbvlC+m6ObRAD5Ccr0N2pwkPm6TZf
TLSH DA84233626AF3AD58121AED4C804D725051EC3379F9EBFEB93428B90D93021D7AC96F5
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-27 07:29:42 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 2ea8c7567acb553dad1fb980204cecaad869fea7d5e3eedf214b3c4bd1fb6349

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments