MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdf3026fc888bae6822cb77d25c7fa9ae048c7fad864289d6c43eb8cc836e6f7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fdf3026fc888bae6822cb77d25c7fa9ae048c7fad864289d6c43eb8cc836e6f7
SHA3-384 hash: 021820a27b14c9b00b48bb9c1498b2e0e4b4a8f8e5229873ad2748bd74601414a5431e6bc87edbf04db0d5f74a1eee95
SHA1 hash: 8d0d7417a390415f4901319d88cf8e06bdfa027b
MD5 hash: b962b362a9a77e1615355b97b0bf8c1e
humanhash: magazine-undress-nineteen-oregon
File name:payment slip.iso
Download: download sample
Signature AgentTesla
File size:1'564'672 bytes
First seen:2020-06-10 11:57:16 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:AAHnh+eWsN3skA4RV1Hom2KXMmHa4JR/dsosrgsO46I9o9quw3NF2wQXCmmI0ZDL:3h+ZkldoPK8Ya4dDsWxI9oSQSmxgtx
TLSH 4075CF0273D6D036FFAB92735B69B24156BD7825013385EF23981DB9BA701B1263D3A3
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: futechina.com.cn
Sending IP: 167.88.9.87
From: Account Payables Futechina <account_payable@futechina.com.cn>
Subject: RE: Deposit has been paid
Attachment: payment slip.iso (contains "payment.exe")

AgentTesla SMTP exfil server:
mail.gangajal.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-10 11:56:17 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso fdf3026fc888bae6822cb77d25c7fa9ae048c7fad864289d6c43eb8cc836e6f7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments