MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32308c99b945b33fbdf3c5ecfc0be1b90f74179842a00f4caedc0e344ef2c003. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 32308c99b945b33fbdf3c5ecfc0be1b90f74179842a00f4caedc0e344ef2c003
SHA3-384 hash: e87170549cdce707ec067da7c36114a8f2981ebb70140f984ea7c8319a91a832a1ac7e9146e0e760231e1ceb86e349ae
SHA1 hash: 92126c2ba41390c12a63f576203d008b811f4231
MD5 hash: 7e2ceaa6825299fb446c0682323a36af
humanhash: island-six-golf-earth
File name:DUNCAN PO ORDER.img
Download: download sample
Signature AgentTesla
File size:530'432 bytes
First seen:2020-10-16 13:55:38 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:iLju3R5Ow9aUQ19c+EIyTxjrtPYPjkH+rs:CSBD9+19cHzTxXIY
TLSH B9B47DBCFAC4E56DF90E4C72C89C08E5922C7C9F5E47F107A8172AC8DE6A541DAB10B5
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: duncanengltd.com
Sending IP: 45.88.3.117
From: Jay Chao <jaychao@duncanengltd.com>
Subject: DUNCAN ENGINEERING LIMITED ORDER
Attachment: DUNCAN PO ORDER.img (contains "DUNCAN PO ORDER.exe")

AgentTesla FTP exfil server:
server.siaemic.cam:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-10-16 10:41:11 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 32308c99b945b33fbdf3c5ecfc0be1b90f74179842a00f4caedc0e344ef2c003

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments