MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8499e1887e0fab31d1467474b1a0eb87638397685129de5971100e7ae05eee37. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8499e1887e0fab31d1467474b1a0eb87638397685129de5971100e7ae05eee37
SHA3-384 hash: 2bedb23b60e8bf19f508f0d9c0b250a89f62a140b7b6ddc7344bf215a5b5be359733aca96e9aca4285d32850109e8343
SHA1 hash: 6dd46815a83bdcbb74c4c8b5e29bbabb7b12af93
MD5 hash: 8f50aeeff8ec40a35466e8d9aee61268
humanhash: november-vegan-timing-king
File name:REMITTANCE.arj
Download: download sample
Signature AgentTesla
File size:425'175 bytes
First seen:2020-05-20 12:31:14 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:W1d0n8LHUgStLtb1uELD2sFx74xoKlnkJFZEpT/5l7MzAWVLRs56uhm6jieTyrxQ:WQ87INLDBb5R3i5lIk+Mjietn0a
TLSH 579423E1E3AD9953CE8373C055AFC4EB7A9847A0911E399874ACF1F9456738B84CB428
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Pavlina Jeff <jeff@bekeert.com>
Subject: Remittance Advice - KIN103
Attachment: REMITTANCE.arj (contains "REMITTANCE.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-20 12:37:30 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj 8499e1887e0fab31d1467474b1a0eb87638397685129de5971100e7ae05eee37

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments