MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fc616ebde032b854c8a1376b29ed730b1514b0b5f98882f6779e9902a8efc88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1fc616ebde032b854c8a1376b29ed730b1514b0b5f98882f6779e9902a8efc88
SHA3-384 hash: d125f08e8ba9187e7ac08385d91a9ef5d53e51b136408495b8a38ace2a01679e9d2864dfb0d33cf8f3bcf039c81236fd
SHA1 hash: c2ac4f7c2c3f0b7ad2c25aa89ce9d25dd5ae3fbd
MD5 hash: 5f5fad09b50fbd057f9db1f133d44505
humanhash: grey-item-saturn-quiet
File name:786535467Order5645678699987.xlsx.img
Download: download sample
Signature AgentTesla
File size:1'200'128 bytes
First seen:2020-06-29 12:41:37 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:ehjluweOyhbG3Sz+wPGVAuoiKg+sXymEkrdMDPHRKm:mYhbPz+XVjoioBkrdgPHRKm
TLSH CB45E91E7E84F904D13C1E3340EE1A506772A9832723C70F7E89ABA85F517AB3E5625D
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chunenterprise.mooo.com
Sending IP: 5.206.224.221
From: Root User <root@localhost>
Subject: RE: New inquiry-640082334913119449524-gigroup Co.,Ltd
Attachment: 786535467Order5645678699987.xlsx.img (contains "65479Order43546576876455.exe")

AgentTesla SMTP exfil server:
smtp.mail.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-29 12:43:10 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 1fc616ebde032b854c8a1376b29ed730b1514b0b5f98882f6779e9902a8efc88

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments