MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b859661771f9fda43fdcc45d130e19e4cd404aeeda4fa4477ef00eebb499cc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 8b859661771f9fda43fdcc45d130e19e4cd404aeeda4fa4477ef00eebb499cc9
SHA3-384 hash: 73b190609a12b79ed8be5a44e0ff299ac5f127631c5fd82b7b3d6ba64074f3facd19fd93edbf7e9d959309014d2f0df8
SHA1 hash: 79c3785a1386b026cd32ad42875cbe7eac403677
MD5 hash: 691b993b75e8f9d6c5621aebabed7e1e
humanhash: steak-oven-sierra-speaker
File name:RFQ.4414_122.rar
Download: download sample
Signature AgentTesla
File size:481'953 bytes
First seen:2020-07-10 17:56:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:D9jtYMZ0FKGuvLmvgnbl83ftkheT3cFH2KUNeWl23s2h5:DzhZ0FKGuTlnbl83yET3hK2e53z
TLSH E8A42382FA5A9B27E82A13C7942CF2DC7941EE32FBD3D45D60C6E96A8C87C548253453
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hwsrv-744091.hostwindsdns.com
Sending IP: 192.236.163.85
From: Luis Sanchez <eric@victorimerce.com>
Subject: RFQ.4414_122
Attachment: RFQ.4414_122.rar (contains "RFQ.4414_122.exe")

AgentTesla SMTP exfil server:
mail.mehatinfo.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8b859661771f9fda43fdcc45d130e19e4cd404aeeda4fa4477ef00eebb499cc9

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments