MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6570b7b851d045baf06055524b84cc15f73038bb5de573ed82d90cc1d3c4b61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d6570b7b851d045baf06055524b84cc15f73038bb5de573ed82d90cc1d3c4b61
SHA3-384 hash: c47545244bcc1f3d5296e11dae5e0586768ddd4f2c6b90afd92b66d4a4e7ac248257353259e81f1b28ac9b462fb53b5d
SHA1 hash: 5a66de99611510a0a409fc1cd906104e68d1bf46
MD5 hash: a6a97d55cc76dd3febe0a424c600ac52
humanhash: early-uranus-oranges-ohio
File name:QTC.110620.OPE.M14.zip
Download: download sample
Signature AgentTesla
File size:418'673 bytes
First seen:2020-06-08 13:29:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:75p11vKo598HOTdrid7CxMga9heus1lZqr:7jjN5H2B59h41lZqr
TLSH FF9423FDD5C875E05546C63F00CE5AC88BA68CB1A94E42493E65B19F3D223F58CBBE81
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: petronas.com.my
Sending IP: 95.211.208.50
From: PETRONAS CARIGALI SDN BHD<master@petronas.com.my>
Subject: Tender No. QTC.110620.OPE.M14
Attachment: QTC.110620.OPE.M14.zip (contains "QTC.110620.OPE.M14.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-08 13:31:05 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d6570b7b851d045baf06055524b84cc15f73038bb5de573ed82d90cc1d3c4b61

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments