MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf8f615bd09f284b9a0353652050f82b8450e02bf3f1117b4885127d1ae5bb67. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bf8f615bd09f284b9a0353652050f82b8450e02bf3f1117b4885127d1ae5bb67
SHA3-384 hash: fbe49a3dd97429ebcdd671bd8ede05784f3bc29646159132a2273a57b11259ee8c0559c8e198ee93a93ad0a95702a3ff
SHA1 hash: c3245b4bd1e6bd4227a23429cc8e3c4f92699d2d
MD5 hash: 592e0078f680dac68036a6a0f898e79a
humanhash: chicken-aspen-lemon-maine
File name:SHIPMENT DOCUMENTS CI,PL.BL.pdf.img
Download: download sample
Signature AgentTesla
File size:1'376'256 bytes
First seen:2020-10-19 06:30:39 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:pDJ2bQKGQQ4PAErhi21O2+TcF39kGIZZi022etWizitlRV2m:pAbiQFPFhL1Y839CZiP2QWimX2m
TLSH 0955AE1422951F58F07D97764260449083F6BD02CB38C94FBDD97AC92E72F82CB67A9B
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: host3.facelube.com
Sending IP: 209.59.173.188
From: Zahi (APSCO) <cchen@facelube.com>
Subject: RE: shipment details
Attachment: SHIPMENT DOCUMENTS CI,PL.BL.pdf.img (contains "SHIPMENT DOCUMENTS CI,PL.BL.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-19 00:28:23 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img bf8f615bd09f284b9a0353652050f82b8450e02bf3f1117b4885127d1ae5bb67

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments