MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 4 Yara Comments

SHA256 hash: 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6
SHA3-384 hash: a4a4a798a5b93bd7a1dce7003b3043eab96ef63cd07b87aa4b44b687f304b9bf21e4eb3b35f2515c8f03e4f918431ea8
SHA1 hash: 2b95007e06e3a8df3e37e13d8e5b04ba49ca3c80
MD5 hash: a0b5f5ae3e5c584d5d05d3024a6c2719
humanhash: zebra-summer-sad-ack
File name:SOA JUNE.r00
Download: download sample
Signature AgentTesla
File size:241'355 bytes
First seen:2020-06-30 12:26:17 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:4HVoB3tadkwmahcvqwNHDYjb8Zz+JBUtuwcFeQ:4HC3pvpGsV+kQ
TLSH 6034231D04C26B8FB21BC33848E651B65C7B37A663D5D4BC8E057E9494E36C1E6B322A
Reporter @abuse_ch
Tags:AgentTesla r00


Twitter
@abuse_ch
Malspam distributing AgentTesla:

HELO: ibd.net.bd
Sending IP: 103.207.38.153
From: Finance<faisal@ibd.net.bd>
Reply-To: thomasbaby.gulfhousemedical@hotmail.com
Subject: SOA of June 2020
Attachment: SOA JUNE.r00 (contains "SOA JUNE.exe")

AgentTesla SMTP exfil server:
mail.chinagrill.co:587

Intelligence


Mail intelligence
Trap location Impact
Global High
NL Netherlands Low
# of uploads 1
# of downloads 26
Origin country US US
ClamAV SecuriteInfo.com.MSIL.Kryptik.WOX.4928.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6/
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 12:28:05 UTC
AV detection:18 of 48 (37.50%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 13.33%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 46330a3a95474a2397a39c6fba3950c2b6e3fb0241bb42aafb8f4e3777d75bf6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments