MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6133f686205601875e5f0f777f00be919bb414099ca4a560b2be3b6099fbbfc0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6133f686205601875e5f0f777f00be919bb414099ca4a560b2be3b6099fbbfc0
SHA3-384 hash: 0157e3d3208b4cca61d07d94b9d980cc9c75a43fa99a468dd787b5c66cd575a364d35647202c956f51bb7395446b63e4
SHA1 hash: b1f265136189fa457a2d15809edd88701b8bde20
MD5 hash: 80483f7690bf44977da0985ad6037dc7
humanhash: spring-cold-south-florida
File name:Nuevo orden.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-25 09:36:14 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:MF6ZyzAw8IrsNV1nqFCxTCu9UO6sJ4Nrh:MgZy/kV8YtCc
TLSH DF450124378C1B69D7BDD3B911B1565017F8B9677222E74E3D8C21AC1FA3BC28602B67
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: srv72.palosanto.com
Sending IP: 198.74.57.172
From: pagos <georgina@metering.com.mx>
Subject: RV: nuevo orden MEXICO
Attachment: Nuevo orden.img (contains "Nuevo orden.PDF.exe")

AgentTesla SMTP exfil server:
mail.arigmed.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 6133f686205601875e5f0f777f00be919bb414099ca4a560b2be3b6099fbbfc0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments