MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80c9727d53d6d18d42efc399c3e1d99d8cc4ae207d111e433d1aec26bda1df7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 80c9727d53d6d18d42efc399c3e1d99d8cc4ae207d111e433d1aec26bda1df7b
SHA3-384 hash: cac64cf41b9140b7d2e20ac5ff5d3826b13c6b5143751977d0d1795cb2f1cf96a9f33561e5c2c09499ca8ff1a467fbde
SHA1 hash: dfe617c5322f8f7d8b8eed684bce7bb7fe161291
MD5 hash: 52f8a2d51432da3fdec374c927483a1f
humanhash: november-monkey-winter-golf
File name:Overpaid Invoice.iso
Download: download sample
Signature AgentTesla
File size:665'600 bytes
First seen:2020-06-03 08:54:21 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:KVND+qXBjPSj+R0ppPUmekAoCuiaVjyRVRe5ZWLELd4QtA6UYtPp/H9bD5stI0B3:cNqqXtPU+ysVoCwRy8OL44tDcPp/Hda
TLSH 13E4C040795849CAE96907B784BBAD2503732C1F96F1D89E798FB26507333C7440BE9E
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.kumarilawyers.com
Sending IP: 162.144.42.75
From: YoungIn Engineering Co., Ltd <kiders@yesyoungin.com>
Subject: Overpaid Invoice
Attachment: Overpaid Invoice.iso (contains "Overpaid Invoice.exe")

AgentTesla SMTP exfil server:
mail.impressindia.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 00:08:00 UTC
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 80c9727d53d6d18d42efc399c3e1d99d8cc4ae207d111e433d1aec26bda1df7b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments