MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cebbf814023d3b4df1612474fc174b8e89dfb1e311d43a6558f4fe93bcc13298. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cebbf814023d3b4df1612474fc174b8e89dfb1e311d43a6558f4fe93bcc13298
SHA3-384 hash: 15b22b496e2f9e15a12a7a826344ce8e266080f2ab1f79f9e264c49bcb898a47eb79cf06551e9a5cfc5fd13a10327df8
SHA1 hash: 62734a3efd5129e3ee99daa27735f794f77bc934
MD5 hash: 23086c8a94628483fa6347737a806a16
humanhash: spaghetti-video-north-black
File name:Quotation9344.Scan.iso
Download: download sample
Signature AgentTesla
File size:700'416 bytes
First seen:2020-07-16 10:03:20 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:Al2k4zUcHbZBsnviErmR3TkPEZwdmz2UX1ZNYeqxYJ:A6bZCviX3TkPEZh
TLSH 07E47BDC3950718EC98E8C764954DC3295202C62F7FBD60263DB6D9B7A7D39BCA012B2
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.luckycable.co
Sending IP: 45.95.169.128
From: Lucky Cable Co. <info@luckycable.co>
Subject: R: urgente
Attachment: Quotation9344.Scan.iso (contains "Quotation9344.Scan.exe")

AgentTesla SMTP exfil server:
mail.bosut.mk:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 10:05:08 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso cebbf814023d3b4df1612474fc174b8e89dfb1e311d43a6558f4fe93bcc13298

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments