MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3fd99856ddb871c2c0b674f891296530bf61d16b348358748c114017ce4da129. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3fd99856ddb871c2c0b674f891296530bf61d16b348358748c114017ce4da129
SHA3-384 hash: 3f5fa78a13590c05579d12e7bc3517f917439c41840e9b0dbe48086f4031f66f08888e948c5b0991fcfa152d444185ed
SHA1 hash: a9b3a3bb32d0f01f6eb1e741df4241c95b2d1558
MD5 hash: a915abfe82d282409e390ccbb803791b
humanhash: zebra-blossom-zulu-september
File name:PO253562.7z
Download: download sample
Signature AgentTesla
File size:419'659 bytes
First seen:2020-07-21 06:05:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:riRGFo/g2DdDACX19mZzVU867yZMXrFHkl:CG2hd0CXmzKW0pkl
TLSH 169423598BB4694EEF43C454F6E02D4DF20FCAC6CB02A2050567278D8D9DEE6F2A2197
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.ocurilem.com
Sending IP: 45.95.170.161
From: Richard Millyard <sales@sakhalinprokur.ru>
Subject: Product Order NX-LI-15-0001
Attachment: PO253562.7z (contains "2ACDnBfZL2HJ5cA.exe")

AgentTesla SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-21 06:07:04 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3fd99856ddb871c2c0b674f891296530bf61d16b348358748c114017ce4da129

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments