MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66301a2a7ca484fbba15150dd58b3e37bcc14ef0c56086556a338dfb267fc25e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66301a2a7ca484fbba15150dd58b3e37bcc14ef0c56086556a338dfb267fc25e
SHA3-384 hash: b66dd725dad877cf39b040b1c79eb16b2178f0686bfcecb407621c159209b9a7bdd5e06e5967468289a496485d6a2538
SHA1 hash: 788d88ffd3f35693dfc0c20279241dc000e612df
MD5 hash: b2f3067a8c7d8c22b894a3422c66f592
humanhash: september-timing-quebec-vegan
File name:CV-COVID HEALTH MANAGER_Pdf_________________________________________________________________________.iso
Download: download sample
Signature AgentTesla
File size:1'044'480 bytes
First seen:2020-04-14 17:22:28 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:mPQY3H3PAhHOKcOUIjAtuoi3OkhdS7/h7vvy4ra5Hl8IOkQcXTc6FLKtqXC:QjPPKcOBiXea/tHSh5lQ+rUqXC
TLSH 3E25AF22F2B18433C1732A3D9D6B5654582ABF013E28A9773BE81E4C5F7928139752F7
Reporter abuse_ch
Tags:AgentTesla COVID-19 iso


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 212.32.245.154
From: Ruoxi Zhang <melamenry@gmail.com>
Subject: CV FROM CHINA AS HEALTH MANAGER (COVID 19)
Attachment: CV-COVID HEALTH MANAGER_Pdf_________________________________________________________________________.iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-14 17:35:22 UTC
File Type:
Binary (Archive)
Extracted files:
50
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 66301a2a7ca484fbba15150dd58b3e37bcc14ef0c56086556a338dfb267fc25e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments