MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8a936501a78119adcc3cdeb21166020a7a283fdbc70f96b27ffd8d375853c5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b8a936501a78119adcc3cdeb21166020a7a283fdbc70f96b27ffd8d375853c5a
SHA3-384 hash: 2bd03faece58937a3370e2887812daec0179582b0901c5c137b371ad0fd59f49de5e93d9aaecffcf7918a4490e35695b
SHA1 hash: 71ce7166f770992cb27a506dc6252e9be59f06d8
MD5 hash: 2ef5cb12654beab7792faf08fac95f11
humanhash: north-foxtrot-charlie-finch
File name:TT W.img
Download: download sample
Signature AgentTesla
File size:493'568 bytes
First seen:2020-06-18 09:35:18 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:VQSc6eTRIBqXN2KbDP0qjKOTinlSaC7rGraBHzkYpekcp2GZgA+WTpJt0i5J:Vrc6eTRWtg74OGnUWm5kYpccWzZ
TLSH DFA4F1197698C705C1691B7FC8E7511003BAAD623A72E7193F8D33AE0B533E3960679B
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: derricksl.com
Sending IP: 45.153.241.204
From: nsukererss@derricksl.com
Subject: TR: Payment: Draft TT Wire Copy for Your Due Invoices - Copy Attached
Attachment: TT W.img (contains "TT W.exe")

AgentTesla SMTP exfil server:
mitendiorigin.cf:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-18 10:37:27 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img b8a936501a78119adcc3cdeb21166020a7a283fdbc70f96b27ffd8d375853c5a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments