MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3023d848e7f4f807db49b69cdc82f117f566b44eeddcf7256b0efce6877b40c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3023d848e7f4f807db49b69cdc82f117f566b44eeddcf7256b0efce6877b40c3
SHA3-384 hash: 2248002930e36dd11568499db5bf6da53a5c4135a442a6d51699ce8d1ed5d72d881ed82d9ed047510d36c5d66ae5f91b
SHA1 hash: d209c066519e1e18558decac2ef861fb521c936f
MD5 hash: 97cf0f8f1a03d80a472f7de177e5f930
humanhash: kansas-ack-mike-ack
File name:RFQ7403937.zip
Download: download sample
Signature AgentTesla
File size:276'926 bytes
First seen:2020-08-03 06:59:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:MdAmTerhf8U3vFhCl13BrS1RJd/kp97lXNbs:MbTqhfZrc0fJd/kZX2
TLSH A04423CBC412A5671A96F709DCFF2750E9406558A2F884EB31FC453A7AC09BBD1602DF
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kumbakarna.iixcp.rumahweb.com
Sending IP: 103.247.9.98
From: Elena  <order10@ratorhu.xyz>
Subject: Re: New order-BH-W20070302
Attachment: RFQ7403937.zip (contains "RFQ7403937.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 07:01:06 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3023d848e7f4f807db49b69cdc82f117f566b44eeddcf7256b0efce6877b40c3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments