MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee8e857c964b20981059e024a88fa3d55cd0d4736a8151cc9c3e871e65c49ab2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ee8e857c964b20981059e024a88fa3d55cd0d4736a8151cc9c3e871e65c49ab2
SHA3-384 hash: 5777cbe0ed80cbac99ce67baec8ad8c04dc734e34564155261a2d68f8ecd7c2b163b6b6d1332a34ef4a653b30fc15e91
SHA1 hash: dcc6e9360f82735b2b0a0001ccc04cf1f9e7fbbb
MD5 hash: d671d16c6f9497a9f503c3448d9402b1
humanhash: yankee-tennis-high-potato
File name:RFQ_PO.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-16 06:25:09 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:3g2iNa2k4zUsynZf6uYrcIDwueDJu+CIJk:Q1OnJ6jrcIEueDJVy
TLSH 3C459CD83EE64811C5EE8DB90C91ED305A287EC6F4F1A1B93BCCEE5F3271240D91955A
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp125.iad3a.emailsrvr.com
Sending IP: 173.203.187.125
From: Yasar Tentage & Textile Industries (Pvt) Ltd. <info@yasartentage.com>
Subject: RFQ 1
Attachment: RFQ_PO.IMG (contains "RFQ_PO.exe")

AgentTesla SMTP exfil server:
mail.makezimbetter.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-16 06:27:04 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img ee8e857c964b20981059e024a88fa3d55cd0d4736a8151cc9c3e871e65c49ab2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments