MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8afa8f8608183b76dbcaee261c20b65ca3ca7bea74a77f3816b6e8208885bfb4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8afa8f8608183b76dbcaee261c20b65ca3ca7bea74a77f3816b6e8208885bfb4
SHA3-384 hash: ae5f8e1eafe037a7cb17cd49d1b9e3798a4c83b95582602e9f432d2304d907ff5dbe1944b3580ee1f9bb28e3b9ada487
SHA1 hash: f9e66cb3c8b58cd9f1baaff34bdaa0fe042253df
MD5 hash: 2094e3bd47e4cec9e0b4351d9c511084
humanhash: ceiling-avocado-juliet-jupiter
File name:FAC_Com09011.pdf.iso
Download: download sample
Signature AgentTesla
File size:765'952 bytes
First seen:2020-06-16 12:42:49 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:Ur5NlaFRMb7GKWWUxDz/xTT8Hc0jc/7RULvIBUKrY9mw8Djgj:qL+Mb7hUhZqc0jc/fLemws
TLSH 87F49F62F6A04437C163157F5C0BB77898EAB9D1292817467BF8CC48AF39741F72B192
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: energyworld.co.zw
Sending IP: 185.118.165.172
From: operations@energyworld.co.zw
Subject: PO
Attachment: FAC_Com09011.pdf.iso (contains "FAC_Com09011.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.CryptInjector
Status:
Malicious
First seen:
2020-06-16 12:44:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 8afa8f8608183b76dbcaee261c20b65ca3ca7bea74a77f3816b6e8208885bfb4

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments