MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a1e764d1d4876d907367f1f5a6971c1a989d730a69ef4bdfc330775b053839a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4a1e764d1d4876d907367f1f5a6971c1a989d730a69ef4bdfc330775b053839a
SHA3-384 hash: f741f07a22153235392b4ea6a1e8fa3a9fd8c9bc0ba07a2adfc0cdc450e8edbb9350fe446e724de8639a781f0ce64276
SHA1 hash: 197514eea24a17b452db01d614b4a02623ccb84d
MD5 hash: 987123ffa384577269bfeffeda2b183c
humanhash: muppet-spring-queen-five
File name:Enquiry-KZ190520.rar
Download: download sample
Signature AgentTesla
File size:435'701 bytes
First seen:2020-05-19 07:19:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:ksmkY6qpAPJxtDTFFtTHau66u1OfegVQgjwQX/B2Um:tY6qWjVTFFtTC1seoIY/Bm
TLSH F9942348F4D18A1D584FA6EF8074235E5EB8A3D6980B4C009F3F6A793FD596FA42F604
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mx19.dns.com.cn
Sending IP: 180.76.192.19
From: cnwll07@cnwll.com
Subject: Enquiry Order KZ190520.
Attachment: Enquiry-KZ190520.rar (contains "Enquiry-KZ190520.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-19 07:36:12 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
14 of 48 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 4a1e764d1d4876d907367f1f5a6971c1a989d730a69ef4bdfc330775b053839a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments