MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47d14bc4110595f979b440a026f9b95a8e613def2248fe90e39005c84f0bc251. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 47d14bc4110595f979b440a026f9b95a8e613def2248fe90e39005c84f0bc251
SHA3-384 hash: 011496921d7a7edbe3ddbc6adcf4e539e76d13f24489071271bc025be18d8de901a75cf6aa00e939014746fb886ba682
SHA1 hash: 560128994ef1af679cf31c2d90a30153b1eef035
MD5 hash: 7a50f73b932822fcb32d16d363928998
humanhash: idaho-bakerloo-echo-jersey
File name:REQUEST FOR QUOTE.Gz
Download: download sample
Signature AgentTesla
File size:450'027 bytes
First seen:2020-05-06 09:52:18 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:oefIY2xe0/fIsLvYAkLWQZethvV34L37nAsce1fqmEJeMg:osUj/gHlKVoLrnAsnfJV
TLSH 14A4234630E7EF58A2709D094C6F18D499BCBA1B5560FCA00C42F0EBD79FE7C6C45A5A
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: smtp.safemail.it
Sending IP: 147.123.1.124
From: Mohammed A Sayeed <mayyadah@mec.com.jo>
Subject: URGENT RFQ- GACA 2020 PROJECT REF: 2211342
Attachment: REQUEST FOR QUOTE.Gz (contains "xrOwBLtrzkRwApz.exe")

AgentTesla SMTP exfil server:
smtp.lettu.us:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-06 10:27:15 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 47d14bc4110595f979b440a026f9b95a8e613def2248fe90e39005c84f0bc251

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments