MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04671a00105f45f3aa32992ba9b87ebdf0a0c0e3934ade4709bb298bc2fae6a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 04671a00105f45f3aa32992ba9b87ebdf0a0c0e3934ade4709bb298bc2fae6a9
SHA3-384 hash: 5ccff8e95f22bfccb21ac3d4d3ef43b07023c700603a036d5eb466652d7e5bf4c13193b91d484bdc2659863ff7ea8979
SHA1 hash: be657ad0ffa1583ec1d405b5a6bc41eb435ce19c
MD5 hash: d6c9610747ffce7ee41089ef0f904588
humanhash: magnesium-wisconsin-diet-island
File name:QUOTE.iso.zip
Download: download sample
Signature AgentTesla
File size:383'787 bytes
First seen:2020-07-06 08:51:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:iiSA07tCzSazpiRWARW9E7fU1dVgF1P99DKjVzyG8aDWHH0xo49ZoyR5xgE1SF7Q:pSZ7tCzSazJaWGfUnVgFP9Oen0ljou57
TLSH 89842344C18D4CBD637254CD589CC0C6AFE6F6911332D28A77CF9920BE6AE60636BD93
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: uporathy.com
Sending IP: 185.193.38.208
From: info@uporathy.com
Subject: Re:Quote
Attachment: QUOTE.iso.zip (contains "qO2y4lWhtDOA9Ww.exe")

AgentTesla SMTP exfil server:
mail.dedhivala.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-06 08:53:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 04671a00105f45f3aa32992ba9b87ebdf0a0c0e3934ade4709bb298bc2fae6a9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments