MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5ce8c4d2e12543d6c237e1f98c76c6daff01b3e477c40e5abeea39afb7327da0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5ce8c4d2e12543d6c237e1f98c76c6daff01b3e477c40e5abeea39afb7327da0
SHA3-384 hash: 77dd3c6d80cde9b13abf6a5d6079aec2e0ae7221cc1d465b150b57bcc555e8213ec4e52a9dfb163c79694fe33d6c0adb
SHA1 hash: 741102a6813d1561292a8169e1f0dad030db2fc0
MD5 hash: 080e4d79d6178bdc12ab39a8fac1a75f
humanhash: whiskey-asparagus-foxtrot-nevada
File name:Transfer Forms.img
Download: download sample
Signature AgentTesla
File size:1'703'936 bytes
First seen:2020-07-30 07:05:58 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:RHUmUUEkNR9wX4tpJ2S7rZd1u5qVlHNjwTslX7XA:1Um6XEJ7UqVltfl8
TLSH 4675D0057A50E56EC67F8F72D6894800DFF4B8AE8607E38F74C573AF29CB36A9406161
Reporter abuse_ch
Tags:AgentTesla Endurance img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 162-144-100-85.unifiedlayer.com
Sending IP: 162.144.38.36
From: PAY-U <enquiry@oxy99.in>
Reply-To: PAY-U <account@payu.com>
Subject: INCORRECT BANK DETAILS FOR PAYMENT
Attachment: Transfer Forms.img (contains "Transfer Forms.scr")

AgentTesla SMTP exfil server:
mail.northwestpowdercoating.co.uk:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-07-30 07:07:13 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 5ce8c4d2e12543d6c237e1f98c76c6daff01b3e477c40e5abeea39afb7327da0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments