MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e78aa85922018b413509d75dccf85092e59d53e21550fdc00471727fe952f5e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e78aa85922018b413509d75dccf85092e59d53e21550fdc00471727fe952f5e1
SHA3-384 hash: 50c1fb068f65f52f8b0d69a6f8bfdf59ed3a985b9685ce2db263544342687b081e177cec788b81060b8388611c6b7d9c
SHA1 hash: 522ac2e377300850cc26d24dd1f7bb37d18f57ae
MD5 hash: 5c529c3c57642f9b60c7fab157d5daae
humanhash: lake-equal-pluto-sweet
File name:URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE AUGUST 25TH 2020.IMG
Download: download sample
Signature AgentTesla
File size:1'310'720 bytes
First seen:2020-08-19 11:21:43 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:8E93enDhZ56UbdJ99Aev+jwsggaLmzvxf18ie3gq5S9FopyPrnQWZ:7QDX56UfHAev0lSijq5a6pyPrQWZ
TLSH 3855F11122D5A25CC8292B745E42571C07F4AC529222C6D9BECF32AA5F3EFCBD72435E
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: alnassar.com.sa
Sending IP: 162.244.93.110
From: LEE JUN WOO <angalos@hec-kr.com>
Reply-To: LEE JUN WOO <angalos@hec-kr.com>
Subject: URGENT [HYUNDAI MOTOR CCPP] DC & UPS SYSTEM / RFQ Issuance / Cut-off date : 2020-08-25
Attachment: URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE AUGUST 25TH 2020.IMG (contains "URGENT UHP RFQ E010 RFQ FOR DC UPS SYSTEM CUT OFF DATE AUGUST 25TH 2020.exe")

AgentTesla SMTP exfil server:
smtp.seldon-petroleum.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-19 01:24:00 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img e78aa85922018b413509d75dccf85092e59d53e21550fdc00471727fe952f5e1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments