MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da15cbf3226ce16a02a69b8f4fcff772f97bc14030f0be64d1c100b14a09130e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: da15cbf3226ce16a02a69b8f4fcff772f97bc14030f0be64d1c100b14a09130e
SHA3-384 hash: 18ac86df436e36adb8c9773eeeb0a4a55fa2044834faebb01ff65b34c66d2f470f5e1e5a011d299afb0cc99db8a54355
SHA1 hash: 9ecac3c0bb9cd888ec139f5426130146552b88ad
MD5 hash: 02a67abb42115b4b735f53b88443ff71
humanhash: delta-quebec-bluebird-zulu
File name:PO20000990.zip
Download: download sample
Signature AgentTesla
File size:376'389 bytes
First seen:2020-06-29 06:37:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:LFUw4G+NOMZ7KUfydXTmLnAw/T1JADSzMDSvloO1Z03bPgqJezy/hByhQ3AcAhHj:LFU/wVU6dD+/JeDYMSlP1Z03bPt/hByV
TLSH 71842327F4F4370BE50900CFBCABEAA5CBA709795DF3599C859B91E8F9111401A2C81F
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.pickelhost.com
Sending IP: 103.99.1.145
From: 黃淑翎 <celine_huang@formosapackaging.com>
Subject: PO20000990
Attachment: PO20000990.zip (contains "PO20000990.exe")

AgentTesla SMTP exfil server:
mail.amberresidenceng.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-29 02:38:15 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip da15cbf3226ce16a02a69b8f4fcff772f97bc14030f0be64d1c100b14a09130e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments