MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe6d9c5e28460d77be2feb94459e08ef7bd93c35faf0c4ff243800500bb9850e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fe6d9c5e28460d77be2feb94459e08ef7bd93c35faf0c4ff243800500bb9850e
SHA3-384 hash: 89a9cef207a2c67472ec7733e35638d1a63a646e838d233a30a061f6b6f0c2a28774d0059e933d34452e0d0399a55a2f
SHA1 hash: 7f7116b17881d5342319770e3fc1c780cdc5b4f8
MD5 hash: 05025a2704c89f5193fc2a269afde641
humanhash: finch-spring-nevada-lake
File name:Recibo Del Envío.img
Download: download sample
Signature AgentTesla
File size:1'638'400 bytes
First seen:2020-06-18 09:42:09 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:yvldz9vEwKV7edXIlr2WvWp73MF5A1lUHey6nnjqKoeGSnjoX:y/5HSSEhbF5A1lUn6nnjqKoe7o
TLSH 08755D1E7A48D846C63D4172D496C2B023729C9FE605C70F3AC93F4A7FB27872A1B656
Reporter abuse_ch
Tags:AgentTesla DHL ESP geo img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: allofyou.ooguy.com
Sending IP: 2.56.8.156
From: DHL EXPRESS <export@emomo.top>
Subject: Notificación De llegada Del Envío
Attachment: Recibo Del Envío.img (contains "Recibo Del Envío.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-18 10:37:43 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img fe6d9c5e28460d77be2feb94459e08ef7bd93c35faf0c4ff243800500bb9850e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments