MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28ef5cf7600014c66657bc622980b11efbd7c83f44e8bbbedca62ad723f987d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 28ef5cf7600014c66657bc622980b11efbd7c83f44e8bbbedca62ad723f987d5
SHA3-384 hash: 7679bfe54fefe9eca170634755f758f0c2ab8189c44149019bc6dc73a055d738442e8a4b0e52a590726b652bd2e29a46
SHA1 hash: c54b96f94d1556f5ec2f154dd53e4e5a5d1be33d
MD5 hash: f3f3b47b42a15139ab40ce7ab77131a5
humanhash: thirteen-utah-king-avocado
File name:quote pictures.rar
Download: download sample
Signature AgentTesla
File size:1'007'373 bytes
First seen:2020-07-01 16:08:01 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:ziVWKznaSTNO1E4sH76a+f6k2j91HlP0qcD4T5oybHF1NSk:kWKDNxO1E4auas65DTb3n
TLSH 442533D8F61C0E0C9CCC7386D79762269A275A4F19E86085C725CAB9BD07A3FC47F864
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.sunman.net
Sending IP: 163.47.84.12
From: TOTAL MARITIME GROUP <purchasingdept.totalmaritime@outlook.com>
Subject: REQUEST FOR QUOTE
Attachment: quote pictures.rar (contains "qotepictures.exe")

AgentTesla SMTP exfil server:
mail.satram.ga:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-07-01 16:09:07 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 28ef5cf7600014c66657bc622980b11efbd7c83f44e8bbbedca62ad723f987d5

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments