MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e38d1f537262946c8ce813397cb55dc6876971b701459f88577f6a4a180e3d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8e38d1f537262946c8ce813397cb55dc6876971b701459f88577f6a4a180e3d2
SHA3-384 hash: 3884576c568c2986a051eb7bf385d7f5b52977a54af8a5c84440381946a21d9bcd8c67cf24c4db1d865f9e8bd4bbd7ea
SHA1 hash: ba1d2f7463c3eb485696b2d9732dc8beabbd34ed
MD5 hash: a9cf2415ddfec5b8bb62678d65f20a0e
humanhash: vermont-idaho-grey-pizza
File name:Tender no- OYM2563.img
Download: download sample
Signature AgentTesla
File size:1'376'256 bytes
First seen:2020-08-27 05:39:34 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:sXdgseMnCyaNiYHDFEt+8VynrTWS9cvAUllc0zG:stgXTC4n3WScxlc0z
TLSH 2D55E14A032A8B3DDE4CB6BD31A040ADE6316742EB34D1D4EF0F65F85A5B25EE05D2C6
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zimbra161-ind.megavelocity.net
Sending IP: 43.224.137.51
From: LRS Ltd Tendering Team <tendering@lrsservices.in>
Reply-To: Yikha Singa <ozainscott@gmail.com>
Subject: RFQ- OYM/2563 (Re-Bid No. RFQ-OYM/2563)
Attachment: Tender no- OYM2563.img (contains "Tender no- OYM2563.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-27 05:41:05 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 8e38d1f537262946c8ce813397cb55dc6876971b701459f88577f6a4a180e3d2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments