MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3016bd40a3d1750554def776bf94db479a9a8a0e2a437f4a00af671d9e1c828f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3016bd40a3d1750554def776bf94db479a9a8a0e2a437f4a00af671d9e1c828f
SHA3-384 hash: 62cc1a3d5ae901cbcda0a29c3e43e696986b015f13fa44dae0cf6f3a137b0d1c1dc13047a63c5578468790e86b63cb2d
SHA1 hash: 41bc7d6719f63f76131933a1aedf71fd02b3b1a1
MD5 hash: 4d9ff7e79055851e2fe9c47e615a9a72
humanhash: tango-romeo-table-harry
File name:MV ULTRA TBN.rar
Download: download sample
Signature AgentTesla
File size:503'091 bytes
First seen:2020-06-29 03:28:43 UTC
Last seen:2020-06-29 03:34:46 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:L/RfMR1mrfydjDOiRnmYdUMRuwLC0pMaj2ge8pU5QP4cDOOWPUUMihpBdZKCYQxI:LRfqmby5iYkMg/imgeyfO3cUrp4GD2Xn
TLSH 18B4233B99171099518B5C1BB3E32533A0CE2046A03F5E35D433EF6ED66F9F8A016E59
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-29 03:30:06 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3016bd40a3d1750554def776bf94db479a9a8a0e2a437f4a00af671d9e1c828f

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments