MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79f2f44319e8f915e8dc7ee7f660527690132f8f4355e9dd0934d3dc276c0af0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 79f2f44319e8f915e8dc7ee7f660527690132f8f4355e9dd0934d3dc276c0af0
SHA3-384 hash: 700df4320abcba91af20ad7bf7a4f099ba1199a90d2b031a4e483a38646a22401bc105e8e389e5f6d6643e1fa3eca7a9
SHA1 hash: 0e2d04f85cb3db50c8385cf0aea908101aff5d44
MD5 hash: 165c11fd310d5ae8915ebd06faaa61e9
humanhash: carolina-carbon-alabama-march
File name:OVDM-ORDER_pdf.img
Download: download sample
Signature AgentTesla
File size:1'441'792 bytes
First seen:2020-12-03 08:30:29 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:sMdUX2XQ77qf55M28VWww1rTblsbyv5ox5jXBLkrZWDcM4lTwBBg:sMaX2XUqx5MObYzrTWrsDng
TLSH 32658BF1EE07E489D06509F0C81ED24D9D62EF1B5769CD89B948F30956B2A0DCEC89F2
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: park-mx.above.com
Sending IP: 103.224.212.34
From: Marie van der Merwe <thandeka@kbcsa.co.za>
Subject: Order and delivery
Attachment: OVDM-ORDER_pdf.img (contains "PO#GEMINI_pdf.scr")

AgentTesla SMTP exfil server:
mail.gandi.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-12-03 08:31:08 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 79f2f44319e8f915e8dc7ee7f660527690132f8f4355e9dd0934d3dc276c0af0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments