MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3472de11e63ec47e3ce96df4c4bb6b768764139a6c5b2ff36e67443045a633a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3472de11e63ec47e3ce96df4c4bb6b768764139a6c5b2ff36e67443045a633a7
SHA3-384 hash: b0d882cf146312dd0365912dee1255844948ee8bd3fc7aa6272739406c65c70b882d2b5fe38e401cc1a0adb3d2d4b6a8
SHA1 hash: c385a3d2a237309b4a4281401fb889ad9579885a
MD5 hash: bcf129334676cbda3dcd29fe0e3dfa4f
humanhash: venus-cup-maine-artist
File name:USD 67,480.63 Pyament advice note dbs 1040.iso
Download: download sample
Signature AgentTesla
File size:505'856 bytes
First seen:2020-05-13 06:55:59 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:elIIEfuZiG/d86u2CXvtOsJByEl9iITmRJltlMVpaNo3C27cA7JFR:el4GZH86uHJE2lmZt/B6B7vR
TLSH 0DB4027AA3B9992FC35A23B8EC6175091BF198152571F3C83C9EA4F4A7AB3D845403D3
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ns.univ21.net
Sending IP: 211.233.62.61
From: Francesca Weeg - Accounts dept HSBC<treybd@gmail.com>
Subject: fwd: Payment advice note dt. 13.05.2020
Attachment: USD 67,480.63 Pyament advice note dbs 1040.iso (contains "USD 67,480.63 Pyament advice note dbs 1040.exe")

AgentTesla SMTP exfil server:
mail.sidasdp.id:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 07:58:00 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
13 of 31 (41.94%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 3472de11e63ec47e3ce96df4c4bb6b768764139a6c5b2ff36e67443045a633a7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments