MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c41c4d5a0c46799accfacb3b0026889041e6b24753242968eca7b3886c08fef3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c41c4d5a0c46799accfacb3b0026889041e6b24753242968eca7b3886c08fef3
SHA3-384 hash: 9055222f56f2518e38753c11c3a74dfb9e9bb35bc7eff1aeb5b18789a510c604e9babcd04a1a7a30301042e9eb56a587
SHA1 hash: 3028380ad801dabe4d3356a7a160f1130efdb9bd
MD5 hash: 206b2b3b0ed6ca70f53d074a40f28530
humanhash: iowa-wisconsin-indigo-bluebird
File name:Inquiry Order KV200520.rar
Download: download sample
Signature AgentTesla
File size:461'664 bytes
First seen:2020-05-20 12:15:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:PEwFiz7W9q69IP4UezXrao7UZnFzV1w6VsSGj0l:P39q6eRezXracEdv9X80l
TLSH 61A423C6678F1DD66B217622BC96C051CCF693A98C4D08DB703738B1E2686D5F97C970
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.ilogsolution.com
Sending IP: 115.249.90.62
From: Lalit Dhingra <lalit@ca-dnd.com>
Subject: Inquiry Order-KV200520 from KV components, s.r.o.
Attachment: Inquiry Order KV200520.rar (contains "Inquiry Order KV200520.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-20 12:35:44 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
20 of 47 (42.55%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c41c4d5a0c46799accfacb3b0026889041e6b24753242968eca7b3886c08fef3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments