MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e32288d8e354fd679fc100c41ff8eabe73ed2db276e064f2c49d0ad384773e0e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e32288d8e354fd679fc100c41ff8eabe73ed2db276e064f2c49d0ad384773e0e
SHA3-384 hash: 21c6a6b1e0bedf84436fe55c3fec715dd85cd4040aafaf6769153b3fc3a1c4b0acef74a0eff71cc8a5c42db16895125d
SHA1 hash: e0ebaca0c5952fcf05f2320baab1fdb46cda4b52
MD5 hash: 9c7df4628a927fcb0ee62d3c50425fe8
humanhash: romeo-cold-alabama-fifteen
File name:payment notification.r10
Download: download sample
Signature AgentTesla
File size:412'090 bytes
First seen:2020-05-11 14:57:34 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:k6WL8yaURHeKreShsN60URzudkG58lz8llT+nIAb:gNcShsUVuh8x8ub
TLSH 0F9423A3FDB81F3044B44022CBC159199DA97F0B19B7525928DD9A9F8CC37F2297C2A7
Reporter abuse_ch
Tags:AgentTesla r10


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cesa.duckdns.org
Sending IP: 209.182.219.170
From: paymentemail@fnb.co.za
Subject: Payment Notification
Attachment: payment notification.r10 (contains "payment notification.exe")

AgentTesla SMTP exfil server:
zstcznz.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 15:37:28 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar e32288d8e354fd679fc100c41ff8eabe73ed2db276e064f2c49d0ad384773e0e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments