MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 583735ae9de54f4ed2cce99a510a0ebc1eca8f7c56fc87fd3f2be5e864ab0e8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 583735ae9de54f4ed2cce99a510a0ebc1eca8f7c56fc87fd3f2be5e864ab0e8f
SHA3-384 hash: 1f8a568c49610e7d7d5d8b463784fab3b2437f02aa7c7ba7210eac031313298488c11145cac182936c571700f480949a
SHA1 hash: 9fefd87f62ba3e535894b7b7f63518f99aae9746
MD5 hash: 8a884421e641326c8f2e76961a398635
humanhash: mississippi-mars-winter-grey
File name:RFQ SC0054852_PDF.r02
Download: download sample
Signature AgentTesla
File size:365'461 bytes
First seen:2020-07-13 06:28:58 UTC
Last seen:Never
File type: r02
MIME type:application/x-rar
ssdeep 6144:YJSnJjVWJbN+vkEbdTBtcaF16wdu5JkjKU5t9PQ6bwWEBDm7wL24pf4JvgAg:YJ68bAvkEbdTBtcwUkjF5tdQ6bqDm+1j
TLSH F47423D53E10151F3802A6F55F5ADC2213FF8E169928DF9F394A18380FAAC6F958E523
Reporter abuse_ch
Tags:ABB AgentTesla r02


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ABB.COM
Sending IP: 176.9.8.123
From: Manish Pandey <IN-GBS.IMS.MY@ABB.COM>
Subject: ABB Request For Quote SC0054852
Attachment: RFQ SC0054852_PDF.r02 (contains "RFQ SC0054852_PDF.exe")

AgentTesla SMTP exfil server:
smtp.urban.co.th:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-13 06:30:10 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r02 583735ae9de54f4ed2cce99a510a0ebc1eca8f7c56fc87fd3f2be5e864ab0e8f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments