MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96a995e4d1c06bc33d2acdd1e825a52bf92223e981ce2f496d0a615957970665. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 96a995e4d1c06bc33d2acdd1e825a52bf92223e981ce2f496d0a615957970665
SHA3-384 hash: f522e5dfae20d418a0bb16e53fb7fd4b59d38dfbdd10aeffbe78d7b94f6545f157912a054dbf13f781f2a8d79da8d107
SHA1 hash: 985f4df13b8ef3966529b6d3fc5049afbed5d66a
MD5 hash: 26e7ae00735f12521b01dde3c60a2a5a
humanhash: winter-fix-east-yankee
File name:09067_100D_HTM.iso
Download: download sample
Signature AgentTesla
File size:518'144 bytes
First seen:2020-05-06 10:02:22 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:93GyaqGhiZrKqGPkwqtpzFQdWX7WJ71YLooAjb:9Wya93F8vFQdWrc5YkRjb
TLSH 1EB402AC712472DFD867C4B599981CA4EB12B57A077F0213B05F54AEEB8E453CF242B2
Reporter abuse_ch
Tags:AgentTesla FedEx iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.linux66.papaki.gr
Sending IP: 136.243.173.169
From: FedEx <services@FedEx.com>
Subject: One (1) Parcel Delivery
Attachment: 09067_100D_HTM.iso (contains "#09067_100D_HTM.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Geniso
Status:
Malicious
First seen:
2020-05-06 10:36:52 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso 96a995e4d1c06bc33d2acdd1e825a52bf92223e981ce2f496d0a615957970665

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments