MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce9dd6279a09745ef85d3d08842a274be161662e92cfa44069d02a65e25031c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ce9dd6279a09745ef85d3d08842a274be161662e92cfa44069d02a65e25031c0
SHA3-384 hash: d05f553291e8361653e8af629f3dce5f7d5eb89bdff9031f78c01ee7157fc5345f3a17f524db5dfc9437bc3d1d923056
SHA1 hash: 8ca42a39d92a5a370f30f49c56cd1920ebaa6aaf
MD5 hash: 121fefae7c52ff694d6056a7078cf988
humanhash: bulldog-gee-kilo-quebec
File name:TEP-RFQ-E-006_DC and UPS System_rA_200716_scanned from a xerox multifunctional device002.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-07-22 08:44:36 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:pZF/MVyuPUm2iNSbQQJjT6iJct0qCAhfIjJRlUSebcF2scBc8S:pXucm1mQQZ7JcfcjTuSToswc
TLSH 17459D58E3B406EBDB960BF9E0A30500677A6EDA63D6D3092B55FA9C2E337404713E17
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.radheshyamengines.partners
Sending IP: 162.241.204.242
From: JUNWOO LEE (Hyundai Engineering Company) <angalos@hec-kr.com>
Subject: [TongYeong CCPP] DC and UPS System / RFQ Issuance / Cut-off date : 2020-07-29
Attachment: TEP-RFQ-E-006_DC and UPS System_rA_200716_scanned from a xerox multifunctional device002.img (contains "TEP-RFQ-E-006_DC and UPS System_rA_200716_scanned from a xerox multifunctional device002.exe")

AgentTesla SMTP exfil server:
smtp.masterindo.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Ymacco
Status:
Malicious
First seen:
2020-07-22 08:46:08 UTC
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img ce9dd6279a09745ef85d3d08842a274be161662e92cfa44069d02a65e25031c0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments