MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b77b6eb8155754d968ac6ed131147679a09b44767e695fdf96fb5b2bf4544c9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b77b6eb8155754d968ac6ed131147679a09b44767e695fdf96fb5b2bf4544c9b
SHA3-384 hash: 16eaf32d75d609010a37112777346f740b7525f56dabf348cfdf4760f835db38081282c40dc5c31320dd19ba1f2b413a
SHA1 hash: 1ea94ff792d5e6a43650e43ec2a05625b48e40c5
MD5 hash: 8bd0d81c4118fca8384af012a40b294e
humanhash: stream-fruit-north-jig
File name:EmiratesNBD_swift_mt103.iso
Download: download sample
Signature AgentTesla
File size:581'632 bytes
First seen:2020-05-11 14:09:54 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:MUehjl2iO3nzIc5Bq/dwTfenQ59V1RKPiq:MXl2iO3BVAeKv
TLSH 51C4BE4023AD6765E17A9BF548B0A111C7B2B62675B9D35E6CCE20CA1BE3F80C941F37
Reporter abuse_ch
Tags:AgentTesla EmiratesNBD iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: keekeejolie.pserver.ru
Sending IP: 80.85.159.32
From: EmiratesNBD Bank <remittance@emiratesNBD.com>
Subject: Emirates NBD - Outward Remittance
Attachment: EmiratesNBD_swift_mt103.iso (contains "EmiratesNBD_swift_mt103.com")

AgentTesla SMTP exfil server:
mail.khokhwmeshmesh.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 14:37:07 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso b77b6eb8155754d968ac6ed131147679a09b44767e695fdf96fb5b2bf4544c9b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments