MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a89cffc93d099d465b14f35b36aa108f614ce25ceb87cb092d8a366b8dfdf603. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a89cffc93d099d465b14f35b36aa108f614ce25ceb87cb092d8a366b8dfdf603
SHA3-384 hash: 62f53a083a5980044639ab4cea11ef448eae2c8e04342dd8ddf1f5d5bb6fe14fd38c2510a381d17186c058a6cb0324e3
SHA1 hash: fc22fdb06f9928d0a0cf60e7b9218f486a5d46ea
MD5 hash: 1bfdcd276e8be240bf08505ad9be2af1
humanhash: victor-two-eleven-magazine
File name:Notificacin de detalles bancarios.iso
Download: download sample
Signature AgentTesla
File size:481'280 bytes
First seen:2020-07-07 18:30:17 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:6ggXgsxqAI4+Gr9OfMPAB5coTNEkyFREVfFqT5APkOKY0FmQg6mLGVYwrZUkr7pG:6ZXPxcf825coBVet4KY0o5SVUCpG
TLSH 3DA4020036A40B76EA3E97F52A25112047F17459AA70F3496FAF31DF26A3B100FA5F1B
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ecs-5iqUK.localdomain
Sending IP: 185.240.246.142
From: Alfonso Perez <afll@evansville.com>
Reply-To: kateyoon@engineer.com
Subject: Re: Re.the respuesta del banco
Attachment: Notificacin de detalles bancarios.iso (contains "Notificación de detalles bancarios.exe")

AgentTesla SMTP exfil server:
smtp.porkbun.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Bluteal
Status:
Malicious
First seen:
2020-07-07 18:32:06 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso a89cffc93d099d465b14f35b36aa108f614ce25ceb87cb092d8a366b8dfdf603

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments