MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c79e38a15ae99b95dd2e0e5901dd23063a03eb9f9ddd1b726c04cea3b64b1842. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c79e38a15ae99b95dd2e0e5901dd23063a03eb9f9ddd1b726c04cea3b64b1842
SHA3-384 hash: 64e4cf849c9d382ba5f7f2a27453584f071eb3c755eb6537ae51f98661d4eace68c9c9be90d0ad471f8c0d5c11067c72
SHA1 hash: e16c9b6aa2fd6ff77f53374e1db44da9b63dee2c
MD5 hash: 4630542bda05023d11b59903bf72a674
humanhash: louisiana-high-indigo-ohio
File name:payment.iso
Download: download sample
Signature AgentTesla
File size:509'952 bytes
First seen:2020-06-18 09:51:11 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:F0c6eTRV+PiRyPwXb78dKTdYfLuGwitmbhS:F36K3qwrE5DyiE
TLSH 7BB4F10532AC8706C476473AC9D6451003BAADA13A73E72E3ECD72AD1B537E75A0678F
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: dbcwool.be
Sending IP: 193.142.59.89
From: ryan096@dbcwool.be
Subject: FW: Payment Receipt & Corresponding Douments.
Attachment: payment.iso (contains "Makave.exe")

AgentTesla SMTP exfil server:
makaveorigin.cf:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso c79e38a15ae99b95dd2e0e5901dd23063a03eb9f9ddd1b726c04cea3b64b1842

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments