MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b7fd71567e54e1908df6aa4a26edf76a08706cd5d7df02a1fd74b4f3f280f09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3b7fd71567e54e1908df6aa4a26edf76a08706cd5d7df02a1fd74b4f3f280f09
SHA3-384 hash: 72cdc816b323e032acd6e784c86433b479a154612a1ebdc0942930019ad7cda73f02065c29d90e248fd19f9967071c8e
SHA1 hash: 29a724b35e98b4fa61b7ae2b56074935c9403571
MD5 hash: d91cff498e6a694d64a0ec82b667bc55
humanhash: georgia-london-black-texas
File name:Shipping documents.pdf.rar
Download: download sample
Signature AgentTesla
File size:415'995 bytes
First seen:2020-06-20 06:54:37 UTC
Last seen:2020-06-20 19:40:42 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:2ImlCR4L/98KuiTPHiORJmR90XjHgrMJW3W:mB9tBmwArhW
TLSH 6A9423517F7FEBD86EB326BF9835FAA49E0CF118C1D4DC6645A499882DB257048B0833
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: jbfmail.com
Sending IP: 103.99.1.170
From: "Arun Davande"<arun_davande@jbfmail.com>
Subject: Shipping Documents // CI 2024000031 // 100 MT to ALTAMIRA
Attachment: Shipping documents.pdf.rar (contains "Shipping documents.pdf.exe")

AgentTesla SMTP exfil server:
mail.microtechlab.in:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-20 06:56:05 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3b7fd71567e54e1908df6aa4a26edf76a08706cd5d7df02a1fd74b4f3f280f09

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments