MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a073ccae277c0c119f279b338f6a84885bb6a65a1542c541eb0f72d89fdffc5f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a073ccae277c0c119f279b338f6a84885bb6a65a1542c541eb0f72d89fdffc5f
SHA3-384 hash: eda75eb9b38dfec72e5ad327b4998fa2e8a38862353f7f26ae490b6b67b05bace6aa7a0bfd0ee218567c25e5ce33c2a5
SHA1 hash: cc3472af5bc74eb34943d650c2b547d75b0ca93a
MD5 hash: 45f90952aa556a2b82f76b6b7b3acecd
humanhash: winter-wolfram-seven-pasta
File name:20200522.rar
Download: download sample
Signature AgentTesla
File size:445'060 bytes
First seen:2020-05-22 07:22:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:YtgtjhvTStUJEtHTgzjJV4/VvIjyGHjpsvUrhlBsKZqESKk:ntj5TS6kTZ5WyqFhvsKzSKk
TLSH 109423A2F3B81E4FEA3425276091D03B717EA044A9D9CFD9931BC28B513DD54B3372A8
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pro152-34.mxout.rediffmailpro.com
Sending IP: 119.252.152.34
From: info@coreplasto.com <info@coreplasto.com>
Subject: Fw: Fwd: 26136 PI 20296629 SO 40129429 Order Balance Due
Attachment: 20200522.rar (contains "20200522.exe")

AgentTesla SMTP exfil server:
mail.mail15.cp247.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-22 07:36:47 UTC
File Type:
Binary (Archive)
Extracted files:
26
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar a073ccae277c0c119f279b338f6a84885bb6a65a1542c541eb0f72d89fdffc5f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments