MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9795a6203c76755c1f63f7b0582bbeff242591294999492769b8421d6ec2325. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c9795a6203c76755c1f63f7b0582bbeff242591294999492769b8421d6ec2325
SHA3-384 hash: e6c03c72fe3f50e3404c3813e12710ea0b100eb54419fb578f6e6a7d8696b2752888ac539c3f3fb16c66cb4f2b13a54c
SHA1 hash: fc92040db3c6f5ece5eb5797652b5f98709c1493
MD5 hash: 3481cc9ce2c37c4699c27ecc556b3c95
humanhash: low-nuts-virginia-lactose
File name:New Order_pdf.rar
Download: download sample
Signature AgentTesla
File size:387'820 bytes
First seen:2020-06-17 11:41:16 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:ypPIR4KZQ1faCd4179TtRhEECIwW6AfF5knuyCEWcTE8NcrGeNVJE9JOxG11uf:ypQSMDb1Jt/kH70HME8NcrGeGJPyf
TLSH C38423D9714E93915E9C239D1BF52095E65BFC1004FDC386A24E8A2F663E161FC78EC2
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.beeinspire.com
Sending IP: 115.124.125.172
From: Prakash International Pvt. Ltd. <raj@prakashchemicals.com>
Subject: Hello Sir/Madam
Attachment: New Order_pdf.rar (contains "T4pjGp8zMcKcf9a.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-17 12:35:55 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c9795a6203c76755c1f63f7b0582bbeff242591294999492769b8421d6ec2325

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments