MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e146ed42f7edb89d9de196c4a17a6b998e5912dc8d5a3ff78a569b0ff32bc0b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e146ed42f7edb89d9de196c4a17a6b998e5912dc8d5a3ff78a569b0ff32bc0b2
SHA3-384 hash: cac7b19cf630af8c2ab53680ae6f69a4de8cdad0821d7cb75c95955a60de494b8e6be15872cd7d5d0457cbfd7e40631c
SHA1 hash: 0eea199920dcc6e4df67802792d29d0c14046c54
MD5 hash: 1b3ed881c9bf48d72bd5990af58a6843
humanhash: earth-april-apart-twelve
File name:Payment Swift-TSB.iso
Download: download sample
Signature AgentTesla
File size:649'216 bytes
First seen:2020-08-13 07:47:37 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:2h9OQYGjF+j4VBSGqVn7x2DuzudXEA3+4tl+C:2RjIYSV7x2Duzkw6l+
TLSH ABD4E07137EA6A50C3AD0EB5152350405BB2381BEFA9C74E3C8C61A91A7AF753241F6B
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cpanel1.eco-campus.ro
Sending IP: 5.35.214.178
From: Sarita Pereira <manager@voom.ro>
Subject: RE: Order # SP2020-001 Payment Document
Attachment: Payment Swift-TSB.iso (contains "Payment Swift-TSB.exe")

AgentTesla SMTP exfil server:
smtp.multilprollc.com:587

AgentTesla SMTP exfil email address:
accounts@multilprollc.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-13 07:49:05 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso e146ed42f7edb89d9de196c4a17a6b998e5912dc8d5a3ff78a569b0ff32bc0b2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments