MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c0e02ab6a859fc79cded728db5b5272da965688bb075eceb46701cbc5c1757e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1c0e02ab6a859fc79cded728db5b5272da965688bb075eceb46701cbc5c1757e
SHA3-384 hash: 8444ca275b8837d4c1eb8ddcc95ed4dca87176a8c7bc5c2704806036474d0c70f97adb6dac1d490f6700ebd910ba6244
SHA1 hash: e754f15fc91ebc086b8022b0975b4e5b1a7985f9
MD5 hash: a8b93f519763ddbf73b21ce0c03fc3b7
humanhash: aspen-butter-sad-black
File name:Due Payments.iso
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-26 09:33:04 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:wFkK5FYPvWLGAu5birnDr5B/yCEzN3cFoeyARpX3BATw:wFTFYPSGAuqnHrKCEzxcFo
TLSH EE45BE9C365475DFC817C972CEA85C60AAA1B47B470BD343B05B22AD9A0D6ABCF110F7
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: joister.net
Sending IP: 103.2.236.240
From: shweta@concorde-eg.com
Reply-To: shweta@concorde-eg.com
Subject: RE: Due Payments/ Buyer Sicem Intl..
Attachment: Due Payments.iso (contains "Due Payments.exe")

AgentTesla SMTP exfil server:
mail.haden-tours.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-26 09:36:44 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 1c0e02ab6a859fc79cded728db5b5272da965688bb075eceb46701cbc5c1757e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments