MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a121326cc19b1577e58f7d158a00f177e17838aa3c58f87442810e03e43d7416. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a121326cc19b1577e58f7d158a00f177e17838aa3c58f87442810e03e43d7416
SHA3-384 hash: 43b56f25d77e737f2bd438c5344ef419ebd29e8a9d2a2f34bce6613624a3c3bd1f6ae7b757f6d0b8bb60248883a3c85f
SHA1 hash: 9423646f5bf1e8292f154ef521f6a4cea105809c
MD5 hash: 9f0b2a3a1f4bc7c5f5c3387f88243906
humanhash: undress-autumn-twenty-lake
File name:New-Sample-QuotationJuly-2020-MT-WEP-60CMM 191016,xls.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-03 06:07:07 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:ngEbQTh8H/mIrbU+Qx0nuaV7KybCKFW3m5s97T:lbQCHRUbaDV7kKMm5sxT
TLSH D245F131631D7F58E1A8FB38A12251010D7A7D776627D71D3C8F32AC1AF1B848A66F92
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp2.hiworks.co.kr
Sending IP: 121.254.168.210
From: 김정훈 <jhkim@ats-tech.co.kr>
Reply-To: "김정훈" <jhkim@ats-tech.co.kr>
Subject: 견적 요청 (7 월 주문)
Attachment: New-Sample-QuotationJuly-2020-MT-WEP-60CMM 191016,xls.img (contains "[New-Sample-Quotation]July-2020-MT-WEP-60CMM (191016),xls.exe")

AgentTesla SMTP exfil server:
smtp.group-lem.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Avemariarat
Status:
Malicious
First seen:
2020-07-03 06:09:05 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img a121326cc19b1577e58f7d158a00f177e17838aa3c58f87442810e03e43d7416

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments