MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8d0d8746df333386fe1343a0a058f35258c7637375cf7e671d7a28c9bd2a5b77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8d0d8746df333386fe1343a0a058f35258c7637375cf7e671d7a28c9bd2a5b77
SHA3-384 hash: 77ae74b6d7dc67ce83e915ab0128261f47ebebc64568a17f2537c46b9440779824100c3372558d64ebb4ad13e8974c5b
SHA1 hash: 8aab83f81ea5150bfbf42b288d65afac33da8686
MD5 hash: 439cf832f76eaf8ab226dca37a476250
humanhash: blue-grey-connecticut-eleven
File name:PI-739.zip
Download: download sample
Signature AgentTesla
File size:396'289 bytes
First seen:2020-06-04 06:42:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:yGzx/SCoP2wckCYNHEA9H/IHan0JwytMFh2jfIu5:y+9YJD9HeuytMDMfd
TLSH 9B8423178B9CFA49403A5D7B49CA7C3782676C3CF925C46EC22ACEDF359056BCA20670
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp79.iad3a.emailsrvr.com
Sending IP: 173.203.187.79
From: exim3@unifreightmovers.com <exim3@unifreightmovers.com>
Subject: Re:PROFORMA INVOICE
Attachment: PI-739.zip (contains "PI-739.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 07:37:27 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 8d0d8746df333386fe1343a0a058f35258c7637375cf7e671d7a28c9bd2a5b77

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments