MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ada0c385d400613ab31b3ee453be7f211bd27bfd4694df72ea1a75b21dd2e76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4ada0c385d400613ab31b3ee453be7f211bd27bfd4694df72ea1a75b21dd2e76
SHA3-384 hash: 1495eff6270c8ec27384e07ed3d2a6e21294451ccaf07e5a7907faf05bc80bfae9b49e0f9478e2eccd80cb34bd5f98a2
SHA1 hash: e48471af1b931cf215fd5341bd7ce0de3c773450
MD5 hash: 12d04084eb616e61dffb995ffcc577f4
humanhash: paris-paris-diet-sweet
File name:MATERIALS SAMPLES.zip
Download: download sample
Signature AgentTesla
File size:405'387 bytes
First seen:2020-06-29 12:40:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:3xH2Kj7FVAFJXe5T5IUWioblXgvgebod8WBnQaUmqIWTscQMaSNB:BWKNVAFZk9PUl0k1jUmnWTscQy
TLSH 5B842332B8FA80894546AF0764E95FC70D335D98AC8D2AAEE4DD00E9C1FB065FD5AC15
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gproxy7-pub.mail.unifiedlayer.com
Sending IP: 70.40.196.235
From: mana@edaraholding.com
Subject: METERIALS EQUIPMENT NEEDED
Attachment: MATERIALS SAMPLES.zip (contains "m.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-29 12:42:08 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 4ada0c385d400613ab31b3ee453be7f211bd27bfd4694df72ea1a75b21dd2e76

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments