MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1c38bdd3ec13c62078a0759fa578aa45475b8bca4d491d3171a6c99a9ed1de2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f1c38bdd3ec13c62078a0759fa578aa45475b8bca4d491d3171a6c99a9ed1de2
SHA3-384 hash: e1270623e6accbb8ee8e2c308ddfd6782ed168cddd7bd8e3d9d0755540ad325c025ac4e7d0bedc9e8b004534ed775e4a
SHA1 hash: 8a0006589bd998dd145551af6f0ca0eb5c8fa45f
MD5 hash: d6fd7761bf2e33253ecb95c3451df9c4
humanhash: sierra-friend-blossom-fifteen
File name:IREQ 202096.ISO
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-03 12:41:16 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:d+yWH0GnTDjlNE8Tb6kPBDColCy6h8YyVG8/96K3gAuR0iBVq2WkO:AD5NE8n6kDRCy6O5Gk9WpBdWk
TLSH 0345F1301340FE76E03E4AB8E15021146F796453F752E3A9BECD61E2339B714CE66BA6
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: esmagroup.com
Sending IP: 45.153.241.182
From: ESMA - Purchase (Orders) <imports.order@esmagroup.com>
Subject: Request for quotation: IREQ 202096
Attachment: IREQ 202096.ISO (contains "IREQ 202096.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-03 12:43:04 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso f1c38bdd3ec13c62078a0759fa578aa45475b8bca4d491d3171a6c99a9ed1de2

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments