MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b3bc77b4c31effd964a4d9281919f72175a9e89c671f68d524c43c8792d4592. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3b3bc77b4c31effd964a4d9281919f72175a9e89c671f68d524c43c8792d4592
SHA3-384 hash: 6cf0cf85167498a8d77630c414f1e1815545becc9b1fcdcaa0289cdff4819345108fd234b63d4dc4d12eb950f0be7ca3
SHA1 hash: 9a159b4e765823279532a5acd9906a7d933dc9d3
MD5 hash: 26531cac4e1bda76ae26959d50990052
humanhash: stairway-zebra-music-black
File name:ORDER-004082020.zip
Download: download sample
Signature AgentTesla
File size:390'184 bytes
First seen:2020-08-04 10:51:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:fpygNsWdx0nW8ZW2E+m94K0mhW6DNEhP6WVm5azrPnbnWOonVYx/bWX6kTIkp/ck:FN3dxyJ02Ehe8BGP6xazrPbWOSWx/Hs/
TLSH 47842309B0F0E5588C422CEE654EAF562BE5A3913BEB4F8C871903E1471BF0ED51DAD8
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: neudoerfler.hu
Sending IP: 156.96.46.79
From: export@neudoerfler.hu
Subject: RE: Commercial Invoice
Attachment: ORDER-004082020.zip (contains "ORDER-004082020.exe")

AgentTesla SMTP exfil server:
mail.ahba.sd:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-04 10:53:09 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3b3bc77b4c31effd964a4d9281919f72175a9e89c671f68d524c43c8792d4592

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments