MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1802f4d04f3eb01fcfd322f841e7141d059a2b0cd9ca73f17d6a2691bca011d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a1802f4d04f3eb01fcfd322f841e7141d059a2b0cd9ca73f17d6a2691bca011d
SHA3-384 hash: 49eb15648ea864ffb542672e7f21837795af5d9abb0baad07c819ef4b96ccc0eab31a935546b6c0641bef6e8af2e2d11
SHA1 hash: d310cbd7aec7368cb9b8793ab40606c5d8c5a349
MD5 hash: ddfa21894dffd6c393ceb894bdf5907b
humanhash: hot-queen-gee-sink
File name:Mormetal MayJune order.zip
Download: download sample
Signature AgentTesla
File size:443'240 bytes
First seen:2020-05-03 08:04:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:KdeLs+R+lq8hALCDh0isxpRyo/2mJvbxBphYp/GmJ9rDenRftjxt0hzT/pnDEPpq:iegVlTCWsxp/3IhPrGfyqhoJp
TLSH C694239C734C937298EE59781902CD37A7B091C801B67C127C6D2A2BB1AFD4B27D6C5B
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.euromaster.es
Sending IP: 82.223.70.126
From: Meliha Surme <export@mormetal.com.tr>
Subject: Fw: new Order
Attachment: Mormetal MayJune order.zip (contains "Mormetal MayJune order.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-03 08:35:42 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a1802f4d04f3eb01fcfd322f841e7141d059a2b0cd9ca73f17d6a2691bca011d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments