MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92ed99f126fb56e2ce180924150d342ad4ea877f3f28af5355af1f7c7ab113d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92ed99f126fb56e2ce180924150d342ad4ea877f3f28af5355af1f7c7ab113d0
SHA3-384 hash: 628afb7d94dbf62f5bce8eafa2ed0328d96852d71a4ac339881073d8ae8d24ced06dfa70c56e95a59c30125a267ef404
SHA1 hash: 92bc88c7ea5cb261b0c487f11eb9ae743e72719e
MD5 hash: fbff61c0083247e67869322b86abc3ac
humanhash: low-yellow-crazy-monkey
File name:ORDER NO 021.ISO
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-16 19:03:22 UTC
Last seen:2020-07-17 05:11:51 UTC
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:RNRLcux2k4zUedAg48YAKtNiHnPlsustG4zM/tLmlu3:Z4Reg4xngnqG4
TLSH E1459DDC3550719EC44E8D768954DC30AA202C22F6FBD20673CB6E9FBA3D596CF152A2
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: s20.bluecast.ae
Sending IP: 213.239.199.114
From: Beth Thompson <beth.thompson@sbcglobal.net>
Subject: PURCHASE ORDER NO:021
Attachment: ORDER NO 021.ISO (contains "fty.exe")

AgentTesla SMTP exfil server:
mail.blackpearl-tours.com:587

AgentTesla SMTP exfil email address:
res@blackpearl-tours.com

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 14:18:10 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 92ed99f126fb56e2ce180924150d342ad4ea877f3f28af5355af1f7c7ab113d0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments