MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7c38782cc83c5dbc4216b59934a87c7a4684ac9d24e3f1074201ef819c6e3df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b7c38782cc83c5dbc4216b59934a87c7a4684ac9d24e3f1074201ef819c6e3df
SHA3-384 hash: da9aeaf279692bc148b5a7a8f0bba0291caab0c816753ea7d479c3874497e429c1f7910cbd388e69c59b24c4228a2b28
SHA1 hash: ce989e474c433e50eea3fb2ad43689b14a197afe
MD5 hash: 8b55c98c9b19ed642e8c640c099d7600
humanhash: cardinal-foxtrot-yankee-fruit
File name:FACTURA_FISCALA-RO81061402-6403840980PDF.iso
Download: download sample
Signature AgentTesla
File size:561'152 bytes
First seen:2020-08-03 13:44:35 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:SgF2iNQ6IvRFKnETXDGuKag52b6yhJwmfKTTS:d1qXvRrzDsaw2bphJ5fKHS
TLSH 7EC4F13122A8BB25D17DA7799020140023F7E457F773E71EFEAD19EA07D6F904A62B06
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: linux577.grserver.gr
Sending IP: 185.4.133.197
From: Nicoleta Novac <Nicoleta.novac@ro.dsv.com>
Subject: DSV Solutions SRL (RO1) - Otopeni - FACTURA FISCALA - RO81061402 - 6403840980 - SWU59080309
Attachment: FACTURA_FISCALA-RO81061402-6403840980PDF.iso (contains "FACTURA_FISCALA-RO81061402-6403840980PDF.exe")

AgentTesla FTP exfil server:
ftp.solarcenter.ro:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 13:46:08 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Malware family:
AgentTesla.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso b7c38782cc83c5dbc4216b59934a87c7a4684ac9d24e3f1074201ef819c6e3df

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments