MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a09dd33c9bfe98cd6fedf320cb14913d59522609b4f4c6fe542d9c55a959577. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 4a09dd33c9bfe98cd6fedf320cb14913d59522609b4f4c6fe542d9c55a959577
SHA3-384 hash: 3075d284879eeede0a5dc44294cb9ec9c3b1042e35ae20f2435d0df02ee9dba815112624f3f8a0eef14fb8328af43ef1
SHA1 hash: 9d29b2131e471f87e3b175a8cac386784c818ca3
MD5 hash: 88117ad93479b00ec5885282c674d0e7
humanhash: sad-carpet-william-music
File name:Medical Equipments Samples.iso
Download: download sample
Signature AgentTesla
File size:1'863'680 bytes
First seen:2020-12-20 12:10:45 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:MCB46b4FQ44Y4X44JDkMdqN5c48ldsz6y0lZ6+RyM+faW6XrA4UlJrmL4Y5Gw1ou:8k
TLSH AE853E02498168CBD7B2D0B0A34DC2D6B38795DCE7EA5FD4AE20E25532CC4B7EB69D41
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sakura13.loopcreate.com
Sending IP: 133.242.50.154
From: Jen Nahid <pedidos@ainea.es>
Subject: Jan 21 Medical Equipments Order
Attachment: Medical Equipments Samples.iso (contains "Medical Equipments Samples.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
198
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 4a09dd33c9bfe98cd6fedf320cb14913d59522609b4f4c6fe542d9c55a959577

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments