MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25de3b99b33d0db9b05084419d092ca4584b815f1e7c69cb4a64deb36901eb51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 25de3b99b33d0db9b05084419d092ca4584b815f1e7c69cb4a64deb36901eb51
SHA3-384 hash: 5b13fe60fdee4e4fe99789014b378dd0608c4d96e9870781b590dcb394efee87bae5868c4c28d66011b879b5d3d9ce80
SHA1 hash: fbf37ff972da4becf9cb6e73476d881889df520d
MD5 hash: 0cbedcd49abb2b4120164fba6117e51b
humanhash: india-echo-august-monkey
File name:URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE 20 AUGUST 2020.IMG
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-08-17 06:22:04 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:gFq53/r7eVqKO3zQ71ZauPn9fXZsBipUydNEmv+YeSZWroaPxRU76+qaZmZ:9EMG/Pn9ftndNz+BrroQ0BZmZ
TLSH CF55F012B2D0C51DC06919368E85930C02B9AD856622E6EA7CCF326E9E7D3DFD701EDD
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.ipmi-cg.com
Sending IP: 89.223.126.111
From: LEE JUN WOO <angalos@hec-kr.com>
Subject: URGENT [HYUNDAI MOTOR CCPP] DC & UPS SYSTEM / RFQ Issuance / Cut-off date : 2020-08-05
Attachment: URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE 20 AUGUST 2020.IMG (contains "URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE 20 AUGUST 2020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-08-17 00:26:36 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 25de3b99b33d0db9b05084419d092ca4584b815f1e7c69cb4a64deb36901eb51

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments