MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4a09dd33c9bfe98cd6fedf320cb14913d59522609b4f4c6fe542d9c55a959577. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 2
| SHA256 hash: | 4a09dd33c9bfe98cd6fedf320cb14913d59522609b4f4c6fe542d9c55a959577 |
|---|---|
| SHA3-384 hash: | 3075d284879eeede0a5dc44294cb9ec9c3b1042e35ae20f2435d0df02ee9dba815112624f3f8a0eef14fb8328af43ef1 |
| SHA1 hash: | 9d29b2131e471f87e3b175a8cac386784c818ca3 |
| MD5 hash: | 88117ad93479b00ec5885282c674d0e7 |
| humanhash: | sad-carpet-william-music |
| File name: | Medical Equipments Samples.iso |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'863'680 bytes |
| First seen: | 2020-12-20 12:10:45 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:MCB46b4FQ44Y4X44JDkMdqN5c48ldsz6y0lZ6+RyM+faW6XrA4UlJrmL4Y5Gw1ou:8k |
| TLSH | AE853E02498168CBD7B2D0B0A34DC2D6B38795DCE7EA5FD4AE20E25532CC4B7EB69D41 |
| Reporter | |
| Tags: | AgentTesla iso |
abuse_ch
Malspam distributing AgentTesla:HELO: sakura13.loopcreate.com
Sending IP: 133.242.50.154
From: Jen Nahid <pedidos@ainea.es>
Subject: Jan 21 Medical Equipments Order
Attachment: Medical Equipments Samples.iso (contains "Medical Equipments Samples.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
198
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.