MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad88a9cfc9757b3907024f7f563998d85b117f9bc8213254d9a9bb126304eeb5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ad88a9cfc9757b3907024f7f563998d85b117f9bc8213254d9a9bb126304eeb5
SHA3-384 hash: 462da8772872a77038d78a0fa49ab685620f767a60d16eecda267818f62e6b3788dc9fa83f5717590ba23eff6ef1db46
SHA1 hash: 30ad2aa18f7005697c780952870c8f2a14d1a517
MD5 hash: 1326da9b01ee967f243a23288fb6d151
humanhash: rugby-bravo-carolina-uncle
File name:Inv_215417_from_Hawthorne_Wire_Services_Ltd._352.pdf.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-20 11:15:54 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:4D6LhK0cGDK9dPhWWLwnkEXsbqzxs5eMfCfWtfQTFdvmzYepr3kyAIYQZ8B+CU:m9rEkxGzerfCHDyY6r0qbaB+C
TLSH 9A459E2D97489F69FA3BE3704406A3474110F8C35EB1E76FABA478D58F4198C0DE7A86
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hawthornewire.com
Sending IP: 96.86.190.25
From: Sales Team<sales@hawthornewire.com>
Subject: Purchase Order
Attachment: Inv_215417_from_Hawthorne_Wire_Services_Ltd._352.pdf.img (contains "Inv_215417_from_Hawthorne_Wire_Services_Ltd._352.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-20 12:34:51 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
16 of 30 (53.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img ad88a9cfc9757b3907024f7f563998d85b117f9bc8213254d9a9bb126304eeb5

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments