MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ae0647bb7ded711c1886b9b71616829dd58a66a7a31f22b21148f8637cd995a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6ae0647bb7ded711c1886b9b71616829dd58a66a7a31f22b21148f8637cd995a
SHA3-384 hash: 6c947ef25c339b532db2f6503fc5cad67304866508df519e10c1b7b3b46b480764b70752245db61c44a51f39daa878b9
SHA1 hash: 02c1b7cf0cb129b1d0121dba0525f55701e424b4
MD5 hash: bd4ed2a5e91188162cbfac82c92d8716
humanhash: edward-uranus-tennessee-angel
File name:USD44,680.85 Payment against invoice 16.07.2020.PDF.iso
Download: download sample
Signature AgentTesla
File size:802'816 bytes
First seen:2020-07-16 08:57:48 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:4SuKv+hOQIDG34kh/W18XFEFvhTcZ3ghFSfzwq/BhV1o:HHhnbaFXFENKZ3Lzwq/BT1o
TLSH CC059F62F2B05432D162267D5C1B5B78583BBE1039285A477BFB7D0CAF39342392B297
Reporter abuse_ch
Tags:AgentTesla HSBC iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 150-95-112-115.conoha.io
Sending IP: 150.95.112.115
From: Paul Hooker - Accounts Dept HSBC<paul.hooker@gmail.com>
Subject: Payment Advice Note From 16.07.2020
Attachment: USD44,680.85 Payment against invoice 16.07.2020.PDF.iso (contains "USD44,680.85 Payment against invoice 16.07.2020.PDF.exe")

AgentTesla SMTP exfil server:
mail.alhaseebcorp.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2020-07-16 08:59:06 UTC
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 6ae0647bb7ded711c1886b9b71616829dd58a66a7a31f22b21148f8637cd995a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments