MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6712fb9b1bd78247ecd2174fd140d3575b5f3ff2482544153343aa08767d0cf1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6712fb9b1bd78247ecd2174fd140d3575b5f3ff2482544153343aa08767d0cf1
SHA3-384 hash: de0b273032b2afa12ca00b47c1de133891ceb52d9d9c416edac53ff225decdcf3ccd488eaa8ddb201240f55a02a72585
SHA1 hash: f6ff73ff815bb0f021031ba91b8a03dbab08ac73
MD5 hash: b678a997aa45977e8d2e49f633a34ff8
humanhash: burger-kitten-william-ceiling
File name:SOLICITUD DE PRESUPUESTO.rar
Download: download sample
Signature AgentTesla
File size:425'041 bytes
First seen:2020-08-10 09:49:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:v3pRipLpUF71WaVrN0RBc9m+Kd9pd9K93grah:/TKL+z0Lcw3d9pHLu
TLSH 48942366430BB513EBB11D695FC1E392AB6672415245FA31FA7FCB7F1AE016C50200EB
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Olga Garcia <esttiare@estiare.es>
Subject: SOLICITUD DE PRESUPUESTO
Attachment: SOLICITUD DE PRESUPUESTO.rar (contains "mon.exe")

AgentTesla SMTP exfil server:
mail.materialsmiquel.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-08-10 09:51:09 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 6712fb9b1bd78247ecd2174fd140d3575b5f3ff2482544153343aa08767d0cf1

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments