MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1028b91b0b9791595912239fec264878577e91461388c1cf75b7a32b9cd8dd12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1028b91b0b9791595912239fec264878577e91461388c1cf75b7a32b9cd8dd12
SHA3-384 hash: 6d42202152ec517874962f34def61d3bfebf302c5b57fe7694dd7921255f9ef2123808d4f2dfcf62488387699dc0e664
SHA1 hash: 59ab4c907eea3058d5d23db4f09d5ab4d25c0de1
MD5 hash: 03995b03cc208118f5713b110c8043bf
humanhash: solar-august-johnny-september
File name:CLOSE DOWN ORDER FROM CDC DATED 4.1.2020.img
Download: download sample
Signature AgentTesla
File size:2'228'224 bytes
First seen:2020-04-07 07:02:42 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:293JCvyd4xE6YY/opp7WtWwrdofIZZSkKJm+gDRnTTlxe:QzdWn++pofIZsgDBTX
TLSH 20A5D02FF65892F3ED1600310AC6CFF9A63A7866332183DBB545AB1545ECFD0297934A
Reporter abuse_ch
Tags:AgentTesla COVID-19 img


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: 162-241-214-72.unifiedlayer.com
Sending IP: 162.241.214.72
From: HR Department <HR@victim-domain>
Subject: (UPDATE COVID-19) CLOSE DOWN ORDER FROM CDC DATED 4.1.2020
Attachment: CLOSE DOWN ORDER FROM CDC DATED 4.1.2020.img (contains "CLOSE DOWN ORDER FROM CDC DATED 4.1.2020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Geniso
Status:
Malicious
First seen:
2020-04-07 07:36:15 UTC
File Type:
Binary (Archive)
Extracted files:
74
AV detection:
15 of 47 (31.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 1028b91b0b9791595912239fec264878577e91461388c1cf75b7a32b9cd8dd12

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments