MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54aad5e582e371a8a04f1e103b254bec84031ecb1bc17d6b69e41191ef79c4be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 54aad5e582e371a8a04f1e103b254bec84031ecb1bc17d6b69e41191ef79c4be
SHA3-384 hash: aeec5565673db7f6cd072722fa0f6e4d35a63214cdeb56fb93e7a64f813592143ae433819757f60d62a454052b9a6c2e
SHA1 hash: 6aa1a73358fd143df7583aa9aed763c01054966b
MD5 hash: e9d0736ef0133e397e2f1342a6f7b92c
humanhash: lamp-hamper-north-triple
File name:PO_67574 SN-3945 187809.rar
Download: download sample
Signature AgentTesla
File size:395'943 bytes
First seen:2020-05-13 10:02:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:Y+OQ9HmOf6J0uLrmEx5owhvYmpF0E+yAjK7/g5z:Y+X9HZSvrN/o2NAGC
TLSH F6842347609B7B4949E3F72E2714A71D55164236102FDFD83B284FEB98F3627E09382A
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gateway30.websitewelcome.com
Sending IP: 192.185.197.25
From: info@kilowatteng.com
Subject: Rfq for Quotation against (Enq # 140319) Urgent
Attachment: PO_67574 SN-3945 187809.rar (contains "PO_67574 SN-3945 187809.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 03:56:55 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
12 of 31 (38.71%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 54aad5e582e371a8a04f1e103b254bec84031ecb1bc17d6b69e41191ef79c4be

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments