MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a45a9e2d6f45c7183d359286a53ade42a77756a7de9f1b8c8a434957b1f33a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6a45a9e2d6f45c7183d359286a53ade42a77756a7de9f1b8c8a434957b1f33a8
SHA3-384 hash: 7ba8383d4fa47b8d6b0918c2860af388c8e5ec1672694f2c794a56c06a62a686afaa7767894a067b400abaccefa2fa7f
SHA1 hash: 797bcfad35c923bb615f191b2dc8ffd3d06890ab
MD5 hash: 340bd5d7d5214c815f1556d538f3d8a8
humanhash: johnny-fruit-november-delta
File name:Cargo Vessel Documents.iso
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-11 12:51:03 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:VrLR1VKPKxnDYdCEqb/VUZQkDgKpXclAN4iQsxPi5zfihPaKx6:9lIKxdEq7VUflXWA4MPMmPE
TLSH 8245F103EE6F8662DC24D9B624B55298466453F68142D33E3ADCB80D0FE339E4B51E9F
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: tit.titserver.net
Sending IP: 96.125.173.240
From: SA Logis Co., Ltd <shipping@salogis.co.kr>
Subject: MV KMC SHIP PORT AGENCY APPOINTMENT
Attachment: Cargo Vessel Documents.iso (contains "Vessel Plan.pdf.exe")

AgentTesla SMTP exfil server:
mail.impressindia.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 16:25:18 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 6a45a9e2d6f45c7183d359286a53ade42a77756a7de9f1b8c8a434957b1f33a8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments