MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 491c8c295ce14c9a30a4e0be73835cd7b346e33b20e38d6db1977bbfd2beb285. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 491c8c295ce14c9a30a4e0be73835cd7b346e33b20e38d6db1977bbfd2beb285
SHA3-384 hash: f79f70502fcf6e7af03722edbefb92245e7d12b8d7bb358fa2e46c05af0591fd1b0b72e98f201811a17ee455df1c1fa8
SHA1 hash: 3196ad2e14502988736344857aa6c5843ecaf912
MD5 hash: 4e291d9665d500a45caf8e9a4975d87a
humanhash: nine-pluto-autumn-river
File name:Order0009867.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-05 07:36:46 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:/cZgvfDBzYxHOXXlolGjVBvN7ku3GFQk56sT0wAU:Umn1zY2XloyVBvasGyk56sT6
TLSH 484523122E0EFD1BCDED6B7954E342555EA1EF10B103A3773AAC36EB1F8478048676A4
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pittini.ml
Sending IP: 23.238.48.9
From: sales <info@pittini.ml>
Reply-To: mohammedazeentrustsave@trustsaveonline.net
Subject: AW:AW:AW
Attachment: Order0009867.img (contains "Invoice.exe")

AgentTesla SMTP exfil server:
smtp.ionos.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-05 08:36:14 UTC
File Type:
Binary (Archive)
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 491c8c295ce14c9a30a4e0be73835cd7b346e33b20e38d6db1977bbfd2beb285

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments