MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b1f84cba07d640381514c3adaaf0fc15c3ce562c3438062b36a0560619c82ac6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | b1f84cba07d640381514c3adaaf0fc15c3ce562c3438062b36a0560619c82ac6 |
|---|---|
| SHA3-384 hash: | dd0b825d345c3cfc774577729911cc30e04c9fd16ffb1e96d471c25d71fa2e403bda4f1581187c4e0878f32e456c8753 |
| SHA1 hash: | f70e2627bb7f81a99ad92389f2cb4ae8e0aa988b |
| MD5 hash: | b82ddab9eec8ce5e1769e22b590ca92a |
| humanhash: | black-tennis-green-xray |
| File name: | mahood.PI.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'245'184 bytes |
| First seen: | 2020-08-04 06:09:09 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:PtNJ8Mrg2iNfbgic+dXHuuin4rmd/EeujQTjGV3/ORXUVh9Ha:PtN3g1Z9c+ZHu14a9EvAq3WRXYX |
| TLSH | D045CF227250D841C39A1736CDCF851847AEAC067571DF2ABDDE339A0A73B639D06BC9 |
| Reporter | |
| Tags: | AgentTesla img |
abuse_ch
Malspam distributing AgentTesla:HELO: mxmexhibitions.com
Sending IP: 185.161.209.26
From: Meltem DEMİRÖREN<info@mxmexhibitions.com>
Reply-To: sales@wavormachinery.com
Subject: RE: RE: order query ! / new order 27-08-2019 . / Order # DSPO 190828A
Attachment: mahood.PI.img (contains "Inv.exe")
AgentTesla SMTP exfil server:
bottleless.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-03 22:58:37 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.