MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3c01ede85f4a4e760f77e216858e1d6af2b4a574bb8f214cb79abd86766a7da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e3c01ede85f4a4e760f77e216858e1d6af2b4a574bb8f214cb79abd86766a7da
SHA3-384 hash: 36531baeb3a5105cbe6e6b1eb19ce8c16b3cf538e3b6579a4675bba377e5a546f1d81a3daaa6d16146c9384e98e38922
SHA1 hash: cb0e9bda9a1a26550d01265f4481ab23d6af32f1
MD5 hash: c0206a636fff6f6c661e228a3f23c705
humanhash: speaker-south-mirror-rugby
File name:Payment Swift MT103 copy_pdf.img.iso
Download: download sample
Signature AgentTesla
File size:808'960 bytes
First seen:2020-06-02 08:42:23 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:lP3Ap0AcJKfs3RrAIaNq4uoLGv/fTAO5Egh82MHFXtBaW/HNWt9u86:tgKKsmIaznKHfsaZhHqFX7g9ut
TLSH 02059F22A2A04432C273167C6F5B77F85C3EBF30296469867BE9DD4C5F397813926287
Reporter abuse_ch
Tags:AgentTesla DHL iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: zmail.bgservice.net
Sending IP: 193.35.40.243
From: DHL Customer Support <office@emk-service.com>
Subject: Fwd :Inward Funds Transfer Notification (MT103)
Attachment: Payment Swift MT103 copy_pdf.img.iso (contains "Payment Swift MT103 copy_pdf.img.exe")

AgentTesla SMTP exfil server:
smtp.kryzlinltd.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 05:50:41 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso e3c01ede85f4a4e760f77e216858e1d6af2b4a574bb8f214cb79abd86766a7da

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments