MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e4bed1da522da99efc35131184be804d19366965d7dfcac572bc2f7e02e024f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5e4bed1da522da99efc35131184be804d19366965d7dfcac572bc2f7e02e024f
SHA3-384 hash: 2213227bf3ad092346df287f8f5904b781a6bf28e8a89f190f00d294f715380ec9234453555f28f5d967a024ccee72b8
SHA1 hash: 508256aa22cd471f50e32e637eb16404bf944f17
MD5 hash: 47a04fb0528e3c246bb2d11736077578
humanhash: carolina-whiskey-seven-skylark
File name:ORDER.rar
Download: download sample
Signature AgentTesla
File size:356'831 bytes
First seen:2020-05-19 06:24:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:Lpb1XofX0lj6oOsD3OIoclQtlldLEY1DkupVJ97qHA6wLPsEjFvPygaIWlki2:LUfX0lPDOGlQX5DX97qtGPf6ywkv
TLSH D374232F126A6B440CB448D4C1764C2FB50DB2C91AC0FBE18FFEB11DEAB94997999D07
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.nevasys.com
Sending IP: 81.23.104.214
From: Ken Lim <info@toyohashi.ed.jp>
Reply-To: abs000010@outlook.com
Subject: New Order Request
Attachment: ORDER.rar (contains "ORDER.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-19 06:36:48 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 5e4bed1da522da99efc35131184be804d19366965d7dfcac572bc2f7e02e024f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments