MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7df6e1d0c223b5ab0a09a5427899cf74edb243f55d29f4e8a154dd4e09ca74d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f7df6e1d0c223b5ab0a09a5427899cf74edb243f55d29f4e8a154dd4e09ca74d
SHA3-384 hash: 1b0921519f543bdca0f0c48df7f07ba16ea9a606a3383477b30da3a165b243fbf5598d55b6548f42bed03c409c05a9c7
SHA1 hash: 52ce8235d48a8e34bf0cba559e90138707709f8c
MD5 hash: e724bfdc0433ace348a13600f1cce9c4
humanhash: berlin-bulldog-table-mockingbird
File name:Fwd Overdue balance request.iso
Download: download sample
Signature AgentTesla
File size:589'824 bytes
First seen:2020-05-21 09:54:08 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:HZKa6DlyOIH1grKsQd/h3aaSMEdLMd0O4v8zU:DtH1grKs3d9Ob4v2U
TLSH D4C4122167ECA759D57A5BF128315A9093B77B876570C60C3C4E60CE2F73B8086A1FA3
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: linux1337.grserver.gr
Sending IP: 176.9.28.118
From: accounts payable <md@hotellanassa.gr>
Subject: Fwd: Overdue balance request
Attachment: Fwd Overdue balance request.iso (contains "Fwd Overdue balance request.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-21 04:46:52 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso f7df6e1d0c223b5ab0a09a5427899cf74edb243f55d29f4e8a154dd4e09ca74d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments