MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb2cc86365feb48a7313a3fd4343dc261f17c9706d93d6d3a615ff18a7d184a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: eb2cc86365feb48a7313a3fd4343dc261f17c9706d93d6d3a615ff18a7d184a1
SHA3-384 hash: c5ff99f0751122176ac43f5f8019bfccf7ba92ad43e5609f1ad3523cd08286c96656de42837fb732351eb913572d67fb
SHA1 hash: 2edf19b7151be97af8ba9f69a9a9272316720282
MD5 hash: 01d7c6a900b783c5e8650d11b70c0116
humanhash: sixteen-shade-florida-april
File name:HALLEY.tbz2
Download: download sample
Signature AgentTesla
File size:465'407 bytes
First seen:2020-05-07 12:20:35 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:/cZSLiMJA9Y/yKW8x2hXrxf/kUzoO4QmAFpcA/UqMt/OO+u5+np47fW:/cZSLiuA9XPFFrB8PqmKfMdZYnGTW
TLSH BAA423C3D5BB55C7EC5BABB7F90EB993E2867CDE856532C5A0A0920EB0024940D4277F
Reporter abuse_ch
Tags:AgentTesla tbz2


Avatar
abuse_ch
Malspam distributing AgentTesla:

Sending IP: 188.164.195.30
From: RADU DOBRE <radu@halleycables.com>
Subject: NEW ORDER - P.O HALLEY PROJECT// UR WEBSITE CONTACT US//
Attachment: HALLEY.tbz2 (contains "HALLEY.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-07 12:36:40 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar eb2cc86365feb48a7313a3fd4343dc261f17c9706d93d6d3a615ff18a7d184a1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments