MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3023d848e7f4f807db49b69cdc82f117f566b44eeddcf7256b0efce6877b40c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 3023d848e7f4f807db49b69cdc82f117f566b44eeddcf7256b0efce6877b40c3 |
|---|---|
| SHA3-384 hash: | 2248002930e36dd11568499db5bf6da53a5c4135a442a6d51699ce8d1ed5d72d881ed82d9ed047510d36c5d66ae5f91b |
| SHA1 hash: | d209c066519e1e18558decac2ef861fb521c936f |
| MD5 hash: | 97cf0f8f1a03d80a472f7de177e5f930 |
| humanhash: | kansas-ack-mike-ack |
| File name: | RFQ7403937.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 276'926 bytes |
| First seen: | 2020-08-03 06:59:11 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:MdAmTerhf8U3vFhCl13BrS1RJd/kp97lXNbs:MbTqhfZrc0fJd/kZX2 |
| TLSH | A04423CBC412A5671A96F709DCFF2750E9406558A2F884EB31FC453A7AC09BBD1602DF |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: kumbakarna.iixcp.rumahweb.com
Sending IP: 103.247.9.98
From: Elena <order10@ratorhu.xyz>
Subject: Re: New order-BH-W20070302
Attachment: RFQ7403937.zip (contains "RFQ7403937.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 07:01:06 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.