MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d68bd9e439c51a6b83a39f05c5b367d177a536e4c26fff6ce97066fe0f15be8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5d68bd9e439c51a6b83a39f05c5b367d177a536e4c26fff6ce97066fe0f15be8
SHA3-384 hash: 63171c5827089e25a9ca2a4bcf6ebc64d07fc5ea6f5467fcbece65c4e4f4188e9ba7477cd373093e9c77239c01fec95f
SHA1 hash: 79b6f46a871ce4ab3f3df3809b82f449c4e0415b
MD5 hash: f992d92544ec461f9f8aa2b01b3b2cb3
humanhash: emma-april-diet-montana
File name:Quotation_PDF___________________________________________________________________________________________________4567890-.gz
Download: download sample
Signature AgentTesla
File size:350'378 bytes
First seen:2020-04-07 18:55:17 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:Dxo8Dpi/LU/KRYOiEcgxp0vHD0rh/iJmYDgJurmlqcVE2ZNdfjTbxYSL+PQL:9hU2yYOiEcgyj0d2MuqgcVNR2SL+Pk
TLSH 7374231BCF21489AB53AF6BD811FA56F57C43B72F061A3506B23EB111261CD1C965FB0
Reporter abuse_ch
Tags:AgentTesla COVID-19 gz


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: cw188-bab-abg206.romania-webhosting.com
Sending IP: 88.212.127.206
From: SERGIO H <jorge@bioline.cl>
Subject: Quotation COVID-19 IgM - IgG Test Spain

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-07 19:37:00 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 5d68bd9e439c51a6b83a39f05c5b367d177a536e4c26fff6ce97066fe0f15be8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments