MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93d1aa184fadc4fa512c0f19fa84e0471cbbaa2b65787876b7565fb7e9f6da03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 93d1aa184fadc4fa512c0f19fa84e0471cbbaa2b65787876b7565fb7e9f6da03
SHA3-384 hash: 0cf77e8ac72c16d954ad97cdcfc5af0895ae9cfa6722ab5aa9279d2662833f3f2eea096d2086547ae84eea390511a93f
SHA1 hash: 6dc5dce97909027553c69090457c3fd544d911e7
MD5 hash: 68aae4748a6e68ee183ee704970c67ef
humanhash: connecticut-potato-double-south
File name:PURCHASE ORDER _ 6WHQ4926847G.IMG
Download: download sample
Signature AgentTesla
File size:1'376'256 bytes
First seen:2020-07-06 08:48:22 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:mZ7GXbYoWBPb0B+Thxy2B7Sb4fyhfHD7JYEAiPnAbH3t27C+OrHoR5SpERq:CSRWJpTm2obqoRPm2jcykOw
TLSH 64559F52E2D04C33D1AB167C8D1B576DA939BE113B3C59463BE81C4CAF3B6933829297
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: box.4ourhome.co.uk
Sending IP: 104.168.246.55
From: Jonna Cabanban <bgv@4ourhome.co.uk>
Subject: RE: NEW PURCHASE ORDER # 6WHQ4926847G
Attachment: PURCHASE ORDER _ 6WHQ4926847G.IMG (contains "Fedex.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DelfFareIt
Status:
Malicious
First seen:
2020-07-06 08:50:07 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 93d1aa184fadc4fa512c0f19fa84e0471cbbaa2b65787876b7565fb7e9f6da03

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments