MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 771839ec3eed276bce97882e827b365378f21e0a949fe4f481e335efc8d0e639. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 771839ec3eed276bce97882e827b365378f21e0a949fe4f481e335efc8d0e639
SHA3-384 hash: d3d2dd7dfe08ed3a33d5697fd315b8720607f56a3b10208fb83490079fab5860b76eb6722782eae7d92a55b32bebdc4b
SHA1 hash: 4e63e651cc62cc4eb33eea46c7065b589ae722d5
MD5 hash: 155ea69edb011fc63e6d70bee7a19bd4
humanhash: charlie-india-maryland-magazine
File name:IMG-43555_UTR 34444_PDF.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-08-28 06:00:41 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:XuiPs1DxD/A5cgd9dtOWfJ6PKVESXy88docBcsndEI6d:XuiPsXo5VdtOWfw5p+cBcsd8
TLSH 9245299D2B88F902F23E9D3782D1462142B1D1875A13DB4F7EC8DBED6B417CD298A385
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ph.phonicphaseapi.live
Sending IP: 45.95.171.224
From: Ahmed.khalid <info@bisselldirect.co.uk>
Reply-To: Ahmed.khalid <info@phonicphaseapi.live>
Subject: REQUEST FOR QUOTE
Attachment: IMG-43555_UTR 34444_PDF.IMG (contains "urban ashraf today today.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-28 06:02:06 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 771839ec3eed276bce97882e827b365378f21e0a949fe4f481e335efc8d0e639

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments