MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3fd99856ddb871c2c0b674f891296530bf61d16b348358748c114017ce4da129. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 3fd99856ddb871c2c0b674f891296530bf61d16b348358748c114017ce4da129 |
|---|---|
| SHA3-384 hash: | 3f5fa78a13590c05579d12e7bc3517f917439c41840e9b0dbe48086f4031f66f08888e948c5b0991fcfa152d444185ed |
| SHA1 hash: | a9b3a3bb32d0f01f6eb1e741df4241c95b2d1558 |
| MD5 hash: | a915abfe82d282409e390ccbb803791b |
| humanhash: | zebra-blossom-zulu-september |
| File name: | PO253562.7z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 419'659 bytes |
| First seen: | 2020-07-21 06:05:20 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:riRGFo/g2DdDACX19mZzVU867yZMXrFHkl:CG2hd0CXmzKW0pkl |
| TLSH | 169423598BB4694EEF43C454F6E02D4DF20FCAC6CB02A2050567278D8D9DEE6F2A2197 |
| Reporter | |
| Tags: | 7z AgentTesla |
abuse_ch
Malspam distributing AgentTesla:HELO: slot0.ocurilem.com
Sending IP: 45.95.170.161
From: Richard Millyard <sales@sakhalinprokur.ru>
Subject: Product Order NX-LI-15-0001
Attachment: PO253562.7z (contains "2ACDnBfZL2HJ5cA.exe")
AgentTesla SMTP exfil server:
smtp.gmail.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-21 06:07:04 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Unknown
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.