MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79b2d429cb15d25eb2246eb5e2c05cef2fabf246bd55145422a9d46763d19d9f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 79b2d429cb15d25eb2246eb5e2c05cef2fabf246bd55145422a9d46763d19d9f
SHA3-384 hash: 1fc872c9fcd09cdf0738c6a1365c9620204869c8872f1be40d2d5f0a449c2c53204f8e1e49431374b6f7d3ea9e9814ee
SHA1 hash: 7e3be340cf2774aac69544911213f4d0ecdbbccf
MD5 hash: 8ba9f53afead3bce5e4ed1ed0de670f6
humanhash: indigo-tennis-neptune-mexico
File name:Penalty OrderKRA202020882831.rar
Download: download sample
Signature AgentTesla
File size:377'420 bytes
First seen:2020-06-15 12:26:14 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:1JfIzXDkdBGtH3LzD8LxcBTv3ndks3cGRfsaT+386rzogDkA0lzrScJLfWURZxcS:1RGsENzDTv3BzRfsaT+386HWTzNfWUmS
TLSH 5D8423C854097B98CE9089691483DECBD8ED52B1F7D7F5866A7AF00D1DC0B0C4BAE6B4
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cpanel2.cityonlinebd.net
Sending IP: 113.212.108.130
From: admin.itax2@kra.go.ke
Reply-To: admin.itax2@kra.go.ke
Subject: Penalty Order
Attachment: Penalty OrderKRA202020882831.rar (contains "Penalty OrderKRA202020882831.exe")

AgentTesla SMTP exfil server:
mail.chirophysic.co.ke:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-15 12:28:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 79b2d429cb15d25eb2246eb5e2c05cef2fabf246bd55145422a9d46763d19d9f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments