MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9c1b02417fcf267256f4eac8b6d63cd4eacd47bf10f5d5e1fc68c69859e3a259. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9c1b02417fcf267256f4eac8b6d63cd4eacd47bf10f5d5e1fc68c69859e3a259
SHA3-384 hash: 01f0f825b806be8913cd90e520becf16039bda29f9b13fc1f9ee677293729772427e56bbc8595c4fa017b932d9eb760b
SHA1 hash: 6aa105e600ff1c9648a52a6853f1fdadec3d2fe3
MD5 hash: f443e1bc9fa5c4dc74e1f4d4a7db6f4e
humanhash: cardinal-arizona-autumn-minnesota
File name:Summit New orders PO.img
Download: download sample
Signature AgentTesla
File size:5'505'024 bytes
First seen:2020-08-18 10:29:24 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 98304:fvSRCyFf5QAaXFk1mw6FiKZAiWbBAuTUeR4os5g/66Ugw/vojESPd9ZSshpbs:fvSRCyFf5QAaXFk1mw6FiKZA45c41ev4
TLSH 01468F40382BB757F19920B209EA19D4A6DC790C27705937CCDBD62CF69D89B7C9E03A
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kgix-othello.g1-srv1a.filteredmx.net
Sending IP: 50.115.17.184
From: conta@enerplus-dz.com
Subject: Fwd: new order PO 1905211 & 213277
Attachment: Summit New orders PO.img (contains "Summit New orders PO 1905211 & 213277.exe")

AgentTesla SMTP exfil server:
smtp.interportclaering.com:587

AgentTesla SMTP exfil email address:
data@interportclaering.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-18 10:31:06 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img 9c1b02417fcf267256f4eac8b6d63cd4eacd47bf10f5d5e1fc68c69859e3a259

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments