MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81aed9ad9226ae747d98d838638509fc3ca3a12916043110540a77810761bbbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 81aed9ad9226ae747d98d838638509fc3ca3a12916043110540a77810761bbbc
SHA3-384 hash: e9dcd4a0287aae5327c868b25d9dc0cce6695574c68d30504db607ef3fc9f7f6703e01c10014d95a7675621a1c4349ce
SHA1 hash: 918db79eadc885400506df2ecffd58266fe30d50
MD5 hash: 468620f3516856125aecc4060494d048
humanhash: double-black-ceiling-sixteen
File name:Swift.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-09 09:33:12 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:fFr3BoDrsUXsvmfECt63rMqvD/9z4dSJ4mKgfUEprkf1z23aCOO:fFrS3XsOfEz3N4IJn8FO
TLSH CC451A397A81941DEE3E053648F85DC167B0A18B2B12CB8F75C617AC5F076CB7B8624E
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: agrochem.org
Sending IP: 193.142.59.55
From: SALES<sales@agrochem.org>
Subject: Bank transfer credited to your IBAN
Attachment: Swift.img (contains "Swift.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-09 09:35:05 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 81aed9ad9226ae747d98d838638509fc3ca3a12916043110540a77810761bbbc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments