MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b54d0b17da5fcd79b30d388fba2dc8bd679259339491f67d999e52728bb3c32d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b54d0b17da5fcd79b30d388fba2dc8bd679259339491f67d999e52728bb3c32d
SHA3-384 hash: 9c6c8c1249af31137df616c82d672ecf8c94b29c52090cd5bd3de386344b8ec29eca3a67869f3ffb0c55289c569d253e
SHA1 hash: 5cdbda20088aec315fafaa37d3c953b0d8edb948
MD5 hash: a5c339d831f5d98f59ab5d09a5bd30d3
humanhash: stream-venus-bakerloo-washington
File name:RFQ.zip
Download: download sample
Signature AgentTesla
File size:672'407 bytes
First seen:2020-07-17 17:25:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:tEX5scLWaIwI1gV7S5cqbypTZBDwynpNNmka+rSk76J57j64w9IdFoBDNEVWx:k5LRIF1gV7S59yxZBHNNm5fC4w9aFayI
TLSH 0CE423F7D304B91368F10DE3F887648680BDD6AB89601DB508939BD323572B9C71F56A
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: emcochem.ca
Sending IP: 193.142.59.133
From: Charlie MARQUETON <pcummings@emcochem.ca>
Reply-To: Charlie MARQUETON <pcummings@emcochem.ca>
Subject: RFQ 705125
Attachment: RFQ.zip (contains "RFQ.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-17 17:27:05 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b54d0b17da5fcd79b30d388fba2dc8bd679259339491f67d999e52728bb3c32d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments