MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51918297719cc432f09b5efc439f27dc68dba2ccc0d0a2c54ad5e60b8f23a7fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 51918297719cc432f09b5efc439f27dc68dba2ccc0d0a2c54ad5e60b8f23a7fd
SHA3-384 hash: a50e9b6f01fa3f72fa97c06617b5149a1eeb81787e0b86244b4c8277422ba5483f4ddaa338eb7208badd8604e481262a
SHA1 hash: c664014324f7b10a44e501b63900073f66e9f729
MD5 hash: 9d86c28bfcce156fbabf7830984eb917
humanhash: solar-video-oxygen-mars
File name:Document.iso
Download: download sample
Signature AgentTesla
File size:456'704 bytes
First seen:2020-09-21 14:33:28 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:h/ekJZeYxu+qSlLstDpzYqLJ1PzUJPxkGYvdd05ED:NBJIYPLsMxkGYv0eD
TLSH 0FA49E6C3550388FC417CBB58950DD30A7B268B6672BD243F89B59DEAB4DB878F401A3
Reporter cocaman
Tags:AgentTesla iso


Avatar
cocaman
Malicious email (T1566.001)
From: "Liam Noah <procurement@allislandequipment.com>"
Received: "from allislandequipment.com (unknown [192.210.236.135]) "
Date: "21 Sep 2020 16:25:43 +0200"
Subject: "Re: Second order of Lecimax - Payment Copy"
Attachment: "Document.iso"

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-09-21 12:29:40 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 51918297719cc432f09b5efc439f27dc68dba2ccc0d0a2c54ad5e60b8f23a7fd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments