MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc7438f2fd1938b81f54d7880405defd24ddb7fa19489cb0ec520350466f5e55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc7438f2fd1938b81f54d7880405defd24ddb7fa19489cb0ec520350466f5e55
SHA3-384 hash: bcb0197de92194ac66449c3f8ed80ca4417e5d7610ec894bcdb3d7bda2598b0ac0ba86da76fa000598c91d99f2122ba8
SHA1 hash: 1cd42bbcebf50cefa64b04f2e4f021b6ee88c7e9
MD5 hash: 2d5bc3ecbbb0ed17521b019fdbffe81e
humanhash: apart-early-sixteen-south
File name:20SMX0701007N.ISO
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-07-08 06:51:11 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:QXjgbnMmIKCXsLIN4KKD6fpkR+ypsKtvP1QZTQC+ILopSxzbexXDfGI7DaNV0K1e:Okb4uLgpfpkZq8TLAdu
TLSH 7C559E22F6A14433C1631A789C1B57B89C3ABE103D6479C63BE95C4C9F39781397AE93
Reporter abuse_ch
Tags:AgentTesla iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: box.serviceflaet.xyz
Sending IP: 104.168.218.237
From: Josh Morris <vendor@serviceflaet.xyz>
Subject: Wire transfer (20SMX0701006N/20SMX0701007N)
Attachment: 20SMX0701007N.ISO (contains "sssssssss.exe")

AgentTesla SMTP exfil server:
mail.sensar-light.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-08 06:53:05 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso dc7438f2fd1938b81f54d7880405defd24ddb7fa19489cb0ec520350466f5e55

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments