MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe5e91a9a892837b9450400f801a7f3d1b114c0b915026d4ee65922593579a0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fe5e91a9a892837b9450400f801a7f3d1b114c0b915026d4ee65922593579a0f
SHA3-384 hash: 5b2b2ecf3196413a18c9efc0a1f419c9319e14daeb2b51df9c9d631185460fd4cde8ca7180caa19eca2e7f37bb2b5b40
SHA1 hash: 8a3a2d3883611afa97ca97d40afa30612a92bdbc
MD5 hash: 9b2c265aa6f0530f631618ca36f2f1d3
humanhash: harry-georgia-low-july
File name:Payment Advice.iso
Download: download sample
Signature AgentTesla
File size:770'048 bytes
First seen:2020-08-28 06:43:40 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:9uO44DPWt6+zdt6fWJc5bN7O2Cr58rbifuL/HhP5kv6mnZayTQVJi:C36+p4fWJc5bNsSr+fG5aCmnc1VJ
TLSH 4AF42326918CCB62D7FD2BB98428346463E72945293ADF7C3EDF99B277B37410466302
Reporter abuse_ch
Tags:AgentTesla HSBC iso


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.com
Sending IP: 95.211.208.25
From: HSBC Advising Service advising <service.7397080.869088.2981149856@mail.com>
Subject: Payment Advice - Advice Ref:[GLV724206853] / Priority payment / Customer Ref:[5500003304]
Attachment: Payment Advice.iso (contains "Payment Advice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-28 06:45:08 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

iso fe5e91a9a892837b9450400f801a7f3d1b114c0b915026d4ee65922593579a0f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments