MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88c209a9491d22ab2908766b7319e085d5d1d01c923b6543e7899ccccbda6c10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 88c209a9491d22ab2908766b7319e085d5d1d01c923b6543e7899ccccbda6c10
SHA3-384 hash: c6ec38d4c1502c0864d19721e9e22eecbd6b7ecdd5f3c13f008c5cc1584437ae2bc2ab887715491716e114521b563aee
SHA1 hash: 63f81589796699f80cb42bb6f74a73d35c165dfc
MD5 hash: 19c1de8b833b62a40e87fea85052f52d
humanhash: earth-diet-five-georgia
File name:YOUR EQUIPMENT ORDER.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-25 17:29:41 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:IuvZorHazhLxdWcEm867XvButvyIiX2LXuJw3:IuvZm69WcvXvsrD
TLSH F445DF11A35C8A17DC7907F9F4606215037BBD1A64A2D2492ECE31EA7E7BBC30753AD2
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: v238211.serveradd.com
Sending IP: 101.100.238.211
From: Subash Jahorie <info@yourequipmentsuppliers.com>
Reply-To: serhaitoguz34@gmail.com
Subject: RE: Request Quote for YOUR EQUIPMENT
Attachment: YOUR EQUIPMENT ORDER.IMG (contains "YOUR EQUIPMENTNew ORDER .exe")

AgentTesla SMTP exfil server:
mail.orientalkuwait.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-25 16:02:47 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 88c209a9491d22ab2908766b7319e085d5d1d01c923b6543e7899ccccbda6c10

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments