MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d21d5a4ceec6756994974a457e91e5598276783bdeb20a90b366d7137cf9ccb5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d21d5a4ceec6756994974a457e91e5598276783bdeb20a90b366d7137cf9ccb5
SHA3-384 hash: 320128b38d635a9b300bac57b78419d79808ee2b952fd2cfd44995efa71c3f65d9d63bddff394a3ed8abbdeb152e6874
SHA1 hash: 95ffb5e64075e4fc2d4291f247dd4328e9087f7a
MD5 hash: db468e02f6e6e40f542cbb6e84260076
humanhash: victor-hotel-failed-victor
File name:Pictures Of Two Staff With COVID-19 Positive scanned from a xerox multifunctional device001.img
Download: download sample
Signature AgentTesla
File size:1'572'864 bytes
First seen:2020-03-31 12:05:39 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:spX+vbOFLePocAGpW0+9lAxNLkhcn/T+chbgSV:xIepAGM0+9lArLkynVgSV
TLSH 1175E042BBD2D070F4D20D35877386B79ABA7E149F218DD3A3D83D09A9305C0AAB975D
Reporter abuse_ch
Tags:AgentTesla COVID-19 img


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: business64-3.web-hosting.com
Sending IP: 198.187.31.71
From: HR Department <support@sunnyleone.website>
Subject: Corona Virus COVID-19 Pandemic Notice! Notice! Notice!=
Attachment: Pictures Of Two Staff With COVID-19 Positive scanned from a xerox multifunctional device001.img

AgentTesla SMTP exfil server:
smtp.maizinternational.com:587 (208.91.198.143)

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Geniso
Status:
Malicious
First seen:
2020-03-31 12:35:54 UTC
File Type:
Binary (Archive)
Extracted files:
28
AV detection:
20 of 47 (42.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img d21d5a4ceec6756994974a457e91e5598276783bdeb20a90b366d7137cf9ccb5

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments