MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 150845484624f2d122beed2161abc333e67069cedb58072a8b6f5744e7174818. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 150845484624f2d122beed2161abc333e67069cedb58072a8b6f5744e7174818
SHA3-384 hash: 64878146e4ccd6846116c19aa99b0aeb57038f7cccacf06c864d5755fba421d954ac53d4a4a48b22d19dfa87253a5919
SHA1 hash: c62f6c74d7f0c5e8677a588517b9be5f21351b5c
MD5 hash: 4ea9ea00c621c743e4ffdb8d41a0bea6
humanhash: fruit-jig-november-grey
File name:kinghardware Customers Feedback, Spec. Pictures.img
Download: download sample
Signature AgentTesla
File size:1'572'864 bytes
First seen:2020-07-29 06:18:48 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:/c6M88EH6F3KO2Lgkz3GavpT8s+itYzTe52Gqf5nrmvBNSHCjIiW01:/cX1Fq3/vFVU5iBFr
TLSH FF75ADD1D24804DFD0A90E30A0C9980C63FD8EA7D458DE6B3D653DD97AB23879B6374A
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kinghardware.com.tw
Sending IP: 64.56.66.253
From: eabcd.king@kinghardware.com.tw
Subject: RE:RE:RE:RE:Aw:Aw:Aw: kinghardware Customer Feedback Samples, Modifications and Spec. Images Batch: JC62349G
Attachment: kinghardware Customers Feedback, Spec. Pictures.img (contains "Quotation.exe")

AgentTesla C2:
http://claskical.top/max/inc/f5ff2232068056.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-07-29 06:20:09 UTC
AV detection:
13 of 27 (48.15%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 150845484624f2d122beed2161abc333e67069cedb58072a8b6f5744e7174818

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments