MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f26dc50a7db81b180e0377709e63b17b533315c5442b282b424ed8bf93dd805f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f26dc50a7db81b180e0377709e63b17b533315c5442b282b424ed8bf93dd805f
SHA3-384 hash: 5d5f2f8a5a6d61dbdffc3c3f9eaffd386d37dd0564d23498113310b70aff1dc7c753ddbf80d57d715c9ccfe52cb9361b
SHA1 hash: ef89bb74bd3894c7133e769658962db9682c7ea7
MD5 hash: 5237dec1cf0e407192bd426af02b7e7c
humanhash: music-eleven-tennis-wyoming
File name:Payment Invoice.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-20 06:19:31 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:r8epSF8lwQByjMZ6/X0Bq8ibWtAHV6IOMB75m3cvm3gINFtsMi7OVwwB42ZtZ+w:1xBR6cvAOMB76csgINFtTweew
TLSH B245E0B03D9881DAFA7A4670E5621C2016F0F8D961A2D3CD7ED9A35D26E33D2414BF27
Reporter abuse_ch
Tags:AgentTesla Citibank img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 162-144-100-85.unifiedlayer.com
Sending IP: 162.144.38.36
From: Adelbert Citibank <enquiry@oxy99.in>
Reply-To: Adelbert Citibank <enquiry@oxy99.in>
Subject: FW: Invoice Payment - TT Copy Attached
Attachment: Payment Invoice.img (contains "Payment Invoice.scr")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-20 06:21:07 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img f26dc50a7db81b180e0377709e63b17b533315c5442b282b424ed8bf93dd805f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments