MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 679bb531b669ca2ad35f0aa5210c325b2082e753cde721d7e460fb94796fe015. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 679bb531b669ca2ad35f0aa5210c325b2082e753cde721d7e460fb94796fe015
SHA3-384 hash: efdcb446085e295bf0101503fe57ca4e8b19ade53bacd737bb106d9ee7c02284458c993b9fd335690840faf109dfb820
SHA1 hash: 64944760e848b6083caabb65daf038b676813850
MD5 hash: c9aedef173a1cd2e2b0fbef3122dca35
humanhash: five-island-skylark-arizona
File name:Wire.iso
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-07-16 07:18:58 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:qls2k4zUVUMYkiDEN1oZmt52nwNCwjtmSHaG:6DiigPoZmt5yjqa
TLSH 52559FDCE518218EC46ECE32DA74EC3C91A01E12B2E1A0C657C6BD9B7DFCE42C91D661
Reporter abuse_ch
Tags:AgentTesla iso OVH


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtpout1.mo804.mail-out.ovh.net
Sending IP: 79.137.123.220
From: <contact@alpha-buro-faconnage.com>
Subject: Wire
Attachment: Wire.iso (contains "Wire.exe")

AgentTesla SMTP exfil server:
mail.jpmvt.com:587

AgentTesla SMTP exfil email address:
nfarr@jpmvt.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 07:20:07 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 679bb531b669ca2ad35f0aa5210c325b2082e753cde721d7e460fb94796fe015

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments