MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c203177b8cc31e18c21401bb81b72b5d046478e084eb42a65d3772231fc48ed3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c203177b8cc31e18c21401bb81b72b5d046478e084eb42a65d3772231fc48ed3
SHA3-384 hash: 950a3eaba8c357f50992a2ea3abe88aadd3859ec6e659f35191afe9d8fa41975b0ccf86eceb0dddfc28a3c2200278af3
SHA1 hash: 9a38dc8ab47440bfefd34c90ef178bbec9a7a8f1
MD5 hash: 74797880d86441e0ec2ee52167a98be9
humanhash: two-connecticut-kitten-rugby
File name:CFFDA Certificate PDF____________________________________________________________647463.gz
Download: download sample
Signature AgentTesla
File size:331'904 bytes
First seen:2020-04-01 12:36:49 UTC
Last seen:2020-04-02 04:00:42 UTC
File type: gz
MIME type:application/x-rar
ssdeep 6144:yXUktMGpn+1nGavmi2L+YSVHcowYt8Psxn3wkAwlKvZDAlh/ceWFEm:kjn+1nLvP2LrqcolZ6wlyArvgEm
TLSH A964237A1ED0A4DBCB817DE88DCB0F4F7115CA90E12D0B9D29642759BB3BE1D22472D2
Reporter abuse_ch
Tags:AgentTesla COVID-19 gz


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: server.clinicasom.com
Sending IP: 185.76.77.225
From: sales Trading LLC <soporte@clinicasom.com>
Subject: Re: CF&FDA Certificate Test Kits covid-19
Attachment: CFFDA Certificate PDF____________________________________________________________647463.gz

AgentTesla SMTP exfil server:
smtp.epaindemgroup.com:587 (208.91.199.224)

Intelligence


File Origin
# of uploads :
2
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-01 10:02:04 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz c203177b8cc31e18c21401bb81b72b5d046478e084eb42a65d3772231fc48ed3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments