MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 acdfeca957aace9d9b00b600a6f9d1028304c189e5b9026fb465bb835414225c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: acdfeca957aace9d9b00b600a6f9d1028304c189e5b9026fb465bb835414225c
SHA3-384 hash: b8cb90b038239a96b4debbbc2fc1a838c8ed7131a44e659c2790050781f1cc38193fec61c187bf8242331bc438e758d4
SHA1 hash: 4e1051e1bf23b9e32d16b621c0bd4a0a78f855a5
MD5 hash: 78737a179fa182bca9367e9bacb0216e
humanhash: neptune-october-zebra-sweet
File name:INV-080773 Bank Swift Copy 20201405 ,pdf.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-14 13:00:31 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:9fvgjk/vIX1rlGPKoBu0ESy9eXyhfmbocVpTosalG:pjvIXvGPPpje0qfhApFa
TLSH C7454A1223BC47A5FBB1A6F59D586E10D630E9FF9884FA0C1F5034EB06A8F50D53692B
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: carpanelli.com
Sending IP: 103.133.111.162
From: Affinita Ornella <export01@carpanelli.com>
Subject: FW: Payment Information
Attachment: INV-080773 Bank Swift Copy 20201405 ,pdf.img (contains "INV-080773 Bank Swift Copy 20201405 ,pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 13:35:57 UTC
File Type:
Binary (Archive)
Extracted files:
29
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img acdfeca957aace9d9b00b600a6f9d1028304c189e5b9026fb465bb835414225c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments