MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 464fc488ee538b6832dd2df9e98ecc1c44183a1319220ac2715b3581f0bc7f51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 464fc488ee538b6832dd2df9e98ecc1c44183a1319220ac2715b3581f0bc7f51
SHA3-384 hash: 5a8923baa8c90fcf6b570c42b3f6aa603fba6377b7a2dc39d96abcd9545b7d8ff47051139c27a16a13fdd9be40af8ea1
SHA1 hash: c6e533a6e19f7673fbe7e680a24a4b409468f7dd
MD5 hash: 3acff4fd6103dbb22c7f401f0f5e38b2
humanhash: bulldog-mirror-massachusetts-yankee
File name:HELP DESK.zip
Download: download sample
Signature AgentTesla
File size:426'668 bytes
First seen:2020-04-13 17:28:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:CVvnc8kEd4Qxa4Baiz1YrlD48Iwzw3NDEyzEgp:CVfxh24BaKYrJjIwzQNDFzR
TLSH A29423B2383AC9D4976E60B996CC510B5F7833E6DD66131602DCED10A2D8538BB43E6F
Reporter abuse_ch
Tags:AgentTesla COVID-19 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-13 17:35:30 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
20 of 45 (44.44%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 464fc488ee538b6832dd2df9e98ecc1c44183a1319220ac2715b3581f0bc7f51

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
commented on 2020-04-13 17:31:13 UTC

COVID-19 themed malspam distributing AgentTesla:

HELO: cloud.chamroeunfoundation.org
Sending IP: 162.241.211.73
From: Flicks <flicks@xlhorticulture.couk>
Subject: COVID 19 HELP DESK
Attachment: HELP DESK.zip (contains "HELP DESK.exe")

AgentTesla SMTP exfil server:
mail.ppe-eg.com:587 (85.17.28.200)