MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 843b34859c60780492ee7c38e17b7a8712672cfcdec757d1ed9f6796f3397465. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 843b34859c60780492ee7c38e17b7a8712672cfcdec757d1ed9f6796f3397465
SHA3-384 hash: e3ae6b6de23fef0f408cd54bccfcf745d9937e8951581e135c77d0517158605bb9ec4b616a356dc7778d356543c199e6
SHA1 hash: c92f40fbec272753e6fb13c26c6443b123823761
MD5 hash: 0c4053dbdbd357e909fc0f5f58398fd6
humanhash: missouri-hotel-edward-hamper
File name:PRODUCT INQUIRY.zip
Download: download sample
Signature AgentTesla
File size:373'285 bytes
First seen:2020-06-28 06:31:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:oahLRQZucIo/SVukREbsoLXFpheKoxBSLP3ddsqNN2BHSc4ae4K9CXRGq5LCz73:5pwuchKVukREbJXFr0BSEqNr3aK89w3
TLSH 37842332732A4F7775233BFD6841C981F2FA83094DC47E91A8A9C1784ED5293D691EB8
Reporter abuse_ch
Tags:AgentTesla Yahoo zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sonic303-2.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.242.179
From: benjamin entac <benjamin_entac@yahoo.com>
Reply-To: benjamin entac <benjamin_entac@yahoo.com>
Subject: REQUEST FOR QUOTATION/PRODUCT INQUIRY
Attachment: PRODUCT INQUIRY.zip (contains "PRODUCT INQUIRY.exe")

AgentTesla SMTP exfil server:
mail.saharanepal.coop.np:587

AgentTesla SMTP exfil email address:
sijuwa@saharanepal.coop.np

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.SchInject
Status:
Malicious
First seen:
2020-06-28 06:33:05 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 843b34859c60780492ee7c38e17b7a8712672cfcdec757d1ed9f6796f3397465

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments