MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c0bbf634d675e21943bb057b725b97ce7afa9cf06ae0f75527d4521358e6384. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5c0bbf634d675e21943bb057b725b97ce7afa9cf06ae0f75527d4521358e6384
SHA3-384 hash: 47a8fbd6e42843fc1c78e912717c07f1f5ceefbf7ed8d863588e44c3b8ba4fbf27fc3a66443821ebdd494e094204955b
SHA1 hash: 8e2ff3bd945884145ab12e25ea7cfdd04d12490f
MD5 hash: cb0f9d909fb90f803c9e2cab10688db3
humanhash: thirteen-carbon-yankee-blossom
File name:001008803011102_05-12-2020.7z
Download: download sample
Signature AgentTesla
File size:420'987 bytes
First seen:2020-05-12 08:49:01 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:1OLlSNkveL7kkCIZhHASG6GzpfYKzRkLM:1OLl/eLlgbaLM
TLSH 359423751912A238C41FDF3A719C178EE5FA861C431386A8A67A303A5F2B7FB2D94481
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: infolab.cadinor.com
Sending IP: 213.170.44.164
From: Rosalia Becerra <rosaliabecerra3@wanadoo.es>
Subject: Confirmación de saldo el 05-12-2\x0a020
Attachment: 001008803011102_05-12-2020.7z (contains "001008803011102_05-12-2020.exe")

AgentTesla SMTP exfil server:
mail.elhelado.com.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-12 09:36:39 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 5c0bbf634d675e21943bb057b725b97ce7afa9cf06ae0f75527d4521358e6384

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments