MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 94b049056daabf6d1670a3a44b888b2421885489bfab8c86689439936f336a74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 94b049056daabf6d1670a3a44b888b2421885489bfab8c86689439936f336a74
SHA3-384 hash: fe7cdabcb0d953d36b3d41e8a347b09c98ba9fe8354c8ce23518cfabeb5432e66ac93e396952f91e1c52d77d4c914971
SHA1 hash: 8ef33093a84a9adadc1cb88adb5c7b809e2ce229
MD5 hash: 883f986e528e400bf42bce736d9cd537
humanhash: louisiana-august-jig-berlin
File name:Document Delivery.iso
Download: download sample
Signature AgentTesla
File size:765'952 bytes
First seen:2020-06-16 12:56:29 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:Tr5NlaFRMb7GKWWUxDz/xTT8Hc0jcsYcf6y+bm0TrXC4r1Y6O:XL+Mb7hUhZqc0jcAyy+bmczO
TLSH 13F49FE2E5900437C152157F5C1B7778A8EABAD129286746FBE8CC48AF3D741B73B182
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: worldlinkcolombo.net
Sending IP: 209.58.149.114
From: DHL-EXPRESS <janaka@worldlinkcolombo.net>
Subject: DHL-EXPRESS: Document Delivery.
Attachment: Document Delivery.iso (contains "BL Shipping document_PDF.bat")

AgentTesla SMTP exfil server:
smtp.mosaiclayouts.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.CryptInjector
Status:
Malicious
First seen:
2020-06-16 12:58:05 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 94b049056daabf6d1670a3a44b888b2421885489bfab8c86689439936f336a74

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments