MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfbadf9a89598013cf3e100619e4cc7e88aafb401985a1952e0f9450b72fab60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bfbadf9a89598013cf3e100619e4cc7e88aafb401985a1952e0f9450b72fab60
SHA3-384 hash: 73d0c335627b80b37818e4180d9fbbbe356c95fba375544a3669816a8810b85b616594632ec33f8a5a989a439762bd4b
SHA1 hash: d24354cf725848bf73b8f4ccd50a7aefe8ca2de1
MD5 hash: 8328901cbdd085b31b07535f5cb3931c
humanhash: alaska-oscar-delaware-queen
File name:Confirmed Purchase Order price at 670 USD CIF.iso
Download: download sample
Signature AgentTesla
File size:528'384 bytes
First seen:2020-05-06 17:09:06 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:5JPQjTocO2uraSkEXWxcyrrxG64DE32nW:6ocOOpEXWmyrcHBnW
TLSH DDB40299B25171DFC8A7C0729ED86DB8FA51756A533B4213B02F049C9B8E5CBDF042E2
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gmail.com
Sending IP: 176.123.7.98
From: Sohar Diamond Interchange <dipinterchange@gmail.com>
Subject: RE: Confirmed Purchase Order price at 670 USD CIF
Attachment: Confirmed Purchase Order price at 670 USD CIF.iso (contains "Confirmed Purchase Order price at 670 USD CIF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-06 17:36:37 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso bfbadf9a89598013cf3e100619e4cc7e88aafb401985a1952e0f9450b72fab60

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments