MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6226985d033a8d73ee2933c0100b42712552fa2b49a642552da22f135e7bbfba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6226985d033a8d73ee2933c0100b42712552fa2b49a642552da22f135e7bbfba
SHA3-384 hash: 51e6a9525b53ddc9f6b24bbe0db8a05e1b490042b98e096a47dbc8b0a5168e45c5ae062558678618c0dac8c7116d7731
SHA1 hash: 41bce73df421e31296453f1a1dd7c0f9234748f5
MD5 hash: 3b9293ee6c0f478f29c7e3a939a884ed
humanhash: fish-burger-hot-moon
File name:Payment confirmationPDF.img
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-05-11 07:59:27 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:6qfCRk3cwaX0ilxDf4+EdCx/dRYOEYTeKIDTrN:g5Df45dCxVRYOREXrN
TLSH C555D000366C8B2AF0B66BF40AA8D461D7B525AE3851DB9EADD811CF52F4F40D950E3F
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.openhotel.com
Sending IP: 66.116.120.10
From: Jane <mghjobs@madisongrandhotel.com>
Subject: payment confirmation
Attachment: Payment confirmationPDF.img (contains "Payment_confirmationPDF.exe")

AgentTesla SMTP exfil server:
smtp.jpme.org.in:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Avemaria
Status:
Malicious
First seen:
2020-05-12 03:24:00 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 6226985d033a8d73ee2933c0100b42712552fa2b49a642552da22f135e7bbfba

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments