MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09ddafd00ad993e0ee7b29bec21394e275dc68fcb74ab25ac8b75c2eeb9101cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 09ddafd00ad993e0ee7b29bec21394e275dc68fcb74ab25ac8b75c2eeb9101cf
SHA3-384 hash: d83c45a058b3f20e2a4467f529d1f6bb4f3a143985fdfb34ddf12475c7207d7860e2322f20dd8b1b683b8a264b1b5baa
SHA1 hash: f69a221a7e5ab2bf301fa1bea4e6c3b58f327274
MD5 hash: 6e79acb9720c0479f5ac7154af87d765
humanhash: asparagus-orange-cola-river
File name:ALL PRODUCTS - AL MULLA SHEET UPDATE LIST.xle.iso
Download: download sample
Signature AgentTesla
File size:784'384 bytes
First seen:2020-05-19 06:47:43 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:z8JsIitBttf+zZa7oPNr3JfjLxEwC6qEkRSMGsfAapx7UZcffitp:QaBJeK0r5hVC/EwLRV7UZofE
TLSH 10F4AF21F6B04833D1631E798C1BD768982ABE107D2879473BE91D4C6F396B1392B393
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: almullagroup.com
Sending IP: 209.58.149.76
From: Nabeel Mahmood <nabeeldxb@almullagroup.com>
Subject: COMPANY PROFILE - HVAC PRODUCT SUPPLIER
Attachment: ALL PRODUCTS - AL MULLA SHEET UPDATE LIST.xle.iso (contains "ALL PRODUCTS - AL MULLA SHEET UPDATE LIST.xle.bat")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-20 02:46:00 UTC
File Type:
Binary (Archive)
Extracted files:
286
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 09ddafd00ad993e0ee7b29bec21394e275dc68fcb74ab25ac8b75c2eeb9101cf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments