MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b22a6173760b48a5506759d9df463e20b7b8fa8b87301585ea37a818bad7ee0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4b22a6173760b48a5506759d9df463e20b7b8fa8b87301585ea37a818bad7ee0
SHA3-384 hash: 888b8e6775b590c25bd7d4caed71e7d4ee19047c32ccb2b8b28b319254388944f194fa62bb7ffdc8c49370e6eecba54d
SHA1 hash: 0c63add082156a87227464392b60085d89b084c5
MD5 hash: ac0e01c27d58721fe918b10bce5a1670
humanhash: pluto-georgia-sierra-sad
File name:QUOTATION.iso
Download: download sample
Signature AgentTesla
File size:647'168 bytes
First seen:2020-07-16 08:35:17 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:LPusn2k4zUIkhOk7d2fzAbCXT6mCwNr2o2NSzu1PQz/yYt:b9dhOEszAbCXT6Rw5rZ
TLSH EFD48DD83910749EC91E8D768964DC3096202C62F7FBD20773CB6E9F7B3D596DA042A2
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: munipueblonuevo.gob.pe
Sending IP: 156.96.115.78
From: mmonje@munipueblonuevo.gob.pe
Subject: RFQ QUOTATION
Attachment: QUOTATION.iso (contains "QUOTATION.exe")

AgentTesla SMTP exfil server:
mail.radianthospitals.org:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 08:37:04 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 4b22a6173760b48a5506759d9df463e20b7b8fa8b87301585ea37a818bad7ee0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments