MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3bed7364bfc3e1367d400d03aa4f878bdc36b09929a552eba011bee04a9497e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d3bed7364bfc3e1367d400d03aa4f878bdc36b09929a552eba011bee04a9497e
SHA3-384 hash: 908336556ae5ea010d009c1bbc66ed332816c3009994e6375e3bd8d5117d9c8b8b7af1fcc183b7f85b85f424f8bbe973
SHA1 hash: 22bda1a65cd349472387446c33b0057511d8b008
MD5 hash: d78a30b570b18cdfe73eb161ea077837
humanhash: black-louisiana-kansas-steak
File name:PAYMENT SLIP COPY.r00
Download: download sample
Signature AgentTesla
File size:325'372 bytes
First seen:2020-05-11 08:28:51 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:HCAAgCIr0jriFGq0sSc5VMpV09e0ZQy1F0wh0qDyxVyYc8e4+DsnyNT:ETHqSiM0ihHqDyXPc8e4+Dsny1
TLSH 6864236547BD54044CF596F18F27E9AC13943AF9244CE5EA0ADF8183E27B09A331F0AB
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: klt-tach.com
Sending IP: 185.99.2.49
From: KLT-TACH <admin@klt-tach.com>
Subject: SWIFT DOCUMENT
Attachment: PAYMENT SLIP COPY.r00 (contains "PAYMENT SLIP COPY.exe")

AgentTesla SMTP exfil server:
mail.yaprakmoda.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 08:36:56 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 d3bed7364bfc3e1367d400d03aa4f878bdc36b09929a552eba011bee04a9497e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments