MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a31a2a6a3674e8b19c4f6adbf38c56bb5c8be5de3bc00652ec12804451255a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7a31a2a6a3674e8b19c4f6adbf38c56bb5c8be5de3bc00652ec12804451255a6
SHA3-384 hash: b10f96c68fef74407822a2c0cf581425d00785e7b6ad92a3ee0e5bc16ab3bd5b921b6729bf11f6e1f7924f4a77921511
SHA1 hash: 27e21b8644a8f67fc61af5538bc4e9a240253320
MD5 hash: dc9ba296db8488027252a43cf08cdedc
humanhash: foxtrot-pip-one-island
File name:Inquiry.iso
Download: download sample
Signature AgentTesla
File size:509'952 bytes
First seen:2020-08-05 17:12:07 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:xP3SURLZYG2TDB7rxx6ZnspRa3DmnU6+w+5Wj8ngrpiA:xV6FVB4JgYTmU6L+QggQA
TLSH 8DB4E044339D5B66E4FCABF8419C348003BA7D56EE21E3597D8E74F62373B808261A97
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: penascop.com
Sending IP: 95.211.208.41
From: benyapa Nattapong<jayusman@penascop.com>
Subject: URGENT INQUIRY
Attachment: Inquiry.iso (contains "Inquiry.exe")

AgentTesla SMTP exfil server:
smtp.ociii.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-05 17:14:06 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 7a31a2a6a3674e8b19c4f6adbf38c56bb5c8be5de3bc00652ec12804451255a6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments