MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e807d4714f17e7a6461c0ccc29279ff2861e976b05ca8cac18b3581f2a22503b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e807d4714f17e7a6461c0ccc29279ff2861e976b05ca8cac18b3581f2a22503b
SHA3-384 hash: ccf2cec58973d22160e5960bd56de0d3a3194b74a5f8187b2247882523211b41fdd9b3e77bda4676610dac0f6afa191a
SHA1 hash: 9b576d183fb7f3234a8a256bf1104d2c83bbb218
MD5 hash: 445394ff2482ed73cb3e3551517b06eb
humanhash: georgia-wolfram-minnesota-mobile
File name:Payment_Advice.PDF.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-05-19 06:45:51 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:v4nxwlJbcxx400mQACFQ7KXU4UR1iXSKegC:kxeJb/OQQyUriih
TLSH DE45020637F85F29C57EA7B1296450002372792726B2E35C7DDC64CE1F62F82CA66B63
Reporter abuse_ch
Tags:AgentTesla HSBC img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.ence.marketing
Sending IP: 62.138.11.76
From: HSBC Advising Service <advising.service.239713666.829979.2869557088@mail.hsbcnet.hsbc.com>
Subject: Payment Advice - Advice Ref:[GLV518843272] / ACH credits / Customer Ref:[HSBC ACH5784] / Second Party Ref:[AU1TT0000939]
Attachment: Payment_Advice.PDF.img (contains "payment_Advice.PDF.exe")

AgentTesla SMTP exfil server:
mail.orientalkuwait.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-19 07:36:28 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img e807d4714f17e7a6461c0ccc29279ff2861e976b05ca8cac18b3581f2a22503b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments