MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9d8ec763f034011ce26de7e8c52da5fe1890251f7bbbd420944cd25ce4ce293. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d9d8ec763f034011ce26de7e8c52da5fe1890251f7bbbd420944cd25ce4ce293
SHA3-384 hash: 4f8c9ee5077ae81fe43392b4b6d212248f945a6225d8d1e35fe6f5f7d4c328a82b119c8538193c84438a257b3bd278ba
SHA1 hash: 7594d72a12831327e44015b8788b369edc9e1c62
MD5 hash: e36b04e502f8a970bd251d54cb85297c
humanhash: winner-beer-mexico-green
File name:CATALOG RMK TRADING LTD 0022_PDF.iso
Download: download sample
Signature AgentTesla
File size:940'032 bytes
First seen:2020-08-18 11:23:58 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:q0naYU7v1x3kDGCPe9xUApykn4feh7GehtloSs7OnZ0YjcsK:Fu7v1NkSC4UApyk4eJVtGSs7OjcsK
TLSH 3D15CF2BB5D5D5C9E12A43B28E50704633B77C1F6824CD29ECAF712852B1FA212B3D5E
Reporter cocaman
Tags:AgentTesla iso


Avatar
cocaman
Malicious email
From: Carlos RMK <amu@ariplan.es>
Received: from mail.zero11.it (mail.zero11.it [109.233.123.239])
Date: Tue, 18 Aug 2020 00:38:29 -0700
Subject: INQUIRY
Attachment: CATALOG RMK TRADING LTD 0022_PDF.iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-18 06:21:30 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso d9d8ec763f034011ce26de7e8c52da5fe1890251f7bbbd420944cd25ce4ce293

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments