MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef3bf4dc8089dc4a53a7f3c01a0ff834d4a8ad8a66ddd19282e242c1855a2a76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ef3bf4dc8089dc4a53a7f3c01a0ff834d4a8ad8a66ddd19282e242c1855a2a76
SHA3-384 hash: 0794d5c359db443894f74529396f9e16e52362a3e0f5fc596a05d4fdbc6adb6a723716609d1d96856aef80499633d21d
SHA1 hash: 3f4a7e29db1502db328ad7a3d1ce1962dbe04d3f
MD5 hash: 049ad99a204095e2e81226069951a7b1
humanhash: india-california-oklahoma-hydrogen
File name:Purchase Order.iso
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-03 08:42:38 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:6f758gKtFBjOY6sZPK/IC2qsU8NH36gthr81tLP+x8J+cee6IjYtZPLewSuI1SiA:o75yjdpFk8tqu4XLc8J+ceets/5e4
TLSH 0E45F14976685D17CDBD88F4D56221014BF18216359AFBCBADCE31DBA7C2BF02621E83
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.menorallc.com
Sending IP: 178.128.121.84
From: Mehdi Rahbarii <fcopy1@dutahitajaya.co.id>
Subject: Purchase Order
Attachment: Purchase Order.iso (contains "ojZvqGrbTgN6zhJ.exe")

AgentTesla SMTP exfil server:
mail.samudrapanel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 00:25:00 UTC
AV detection:
12 of 31 (38.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso ef3bf4dc8089dc4a53a7f3c01a0ff834d4a8ad8a66ddd19282e242c1855a2a76

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments