MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1f308b79062c7e9aa123e612582e2bc934be19bea80d4d65477999669e7885a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e1f308b79062c7e9aa123e612582e2bc934be19bea80d4d65477999669e7885a
SHA3-384 hash: 99c9e6f64694757fc114357ce2f30aa81dc596e6915869298651a6445e779867600eb4de797e8682612cf21ca9aa30d9
SHA1 hash: 3a8f06c252ad571570d9f06bc19f4bb4fd929fa3
MD5 hash: 917896740992658d66bc764fee6ea1d6
humanhash: kilo-california-skylark-kentucky
File name:ACCOUNT STATEMENT UPDATED.arj
Download: download sample
Signature AgentTesla
File size:388'630 bytes
First seen:2020-06-26 06:14:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:VFEoCHcpWZKQrtjmfhtYSQ15pBw16VO/9oH/4RGmv1ylnuzJY2K5rSqZbqTtgMkv:boHMWZKQlehtY31W6V49KgUmdOu1Yn5d
TLSH 67842311CBA34D42AB6736E788288171B397B5D50CE927EFB69E68D71DC710B0784E0A
Reporter abuse_ch
Tags:AgentTesla arj SendGrid


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: wrqvcdrn.outbound-mail.sendgrid.net
Sending IP: 149.72.205.82
From: Cho <shipping@ibiza.lv>
Subject: RE: RE: RE: RE: RE: RE: Re: Account statement (updated) + TT details.
Attachment: ACCOUNT STATEMENT UPDATED.arj (contains "ACCOUNT STATEMENT (UPDATED).exe")

AgentTesla SMTP exfil server:
sg2plcpnl0180.prod.sin2.secureserver.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 06:16:09 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip e1f308b79062c7e9aa123e612582e2bc934be19bea80d4d65477999669e7885a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments