MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0888129f90369b093625b1d13e7fe4e3d2d5190c96f10e100253b5f5236a009e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0888129f90369b093625b1d13e7fe4e3d2d5190c96f10e100253b5f5236a009e
SHA3-384 hash: 770f23047a4374d993ed9c1920bd8aefe9c34d1a630451f2403b26d034a22f03af1de157a74969c8e6b2e12a722d923a
SHA1 hash: 6d02da37028dbb99661658fa7b54dca9f0ef04f6
MD5 hash: 60ded7d550d1291f051fee85f550a86c
humanhash: echo-double-johnny-single
File name:RFQ20311.pdf.z
Download: download sample
Signature AgentTesla
File size:1'031'451 bytes
First seen:2020-04-30 12:48:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:yTTzTUfyj2NLyUxOpDV4Kn6eqrkOWyQBtVtR:ST/ghFsH6KtVj
TLSH 512533A8F815CF0B7E7AE3DA434A11C0F34807F554495B26ADF9060B63DB414BB6B6AC
Reporter abuse_ch
Tags:AgentTesla geo TUR z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: pensan.com.tr
Sending IP: 156.96.58.98
From: Ali Çiftcioğlu <aliciftcioglu@pensan.com.tr>
Subject: Teklif No: 20311
Attachment: RFQ20311.pdf.z (contains "RFQ20311.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-04-30 13:35:49 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0888129f90369b093625b1d13e7fe4e3d2d5190c96f10e100253b5f5236a009e

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments