MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8cf323a5350778bf8c9c96d33a26e5cac9868d85016b0498db62be76056979f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8cf323a5350778bf8c9c96d33a26e5cac9868d85016b0498db62be76056979f8
SHA3-384 hash: 289afad75f46f2ad6409a530d15e8755a763ba1328ef0c155be2af066d10e86c55f0a260fae0402cb94d9808c374d8e8
SHA1 hash: 6690fde4f5c7571af7b0a12183dee91a502f4ab4
MD5 hash: 766fc081b2d785313d0ec6a5e6d94d46
humanhash: aspen-iowa-pluto-nineteen
File name:price quotation.rar
Download: download sample
Signature AgentTesla
File size:384'363 bytes
First seen:2020-06-12 06:54:41 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:1QNx1JZl9mBRMQrYr6q2pRvX8SPT5pC8T7Tobo89JOrLnK/TDa+NiyQlR8Z:1QNx1JT9OMQrRJdP9pC8Wo8HOvnK/TXf
TLSH 3584239A005FD1A1C10D9A39A8CD76018745FF27EB560A731EBFFA0A6DDE260BD11E07
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: spfilter-3.sel01.mschosting.com
Sending IP: 110.4.44.19
From: Hilmi, Ezhar <ezhar.hilmi@planet1world.com>
Reply-To: Hilmi, Ezhar nealworkrestblades\@yahoo.com
Subject: price quotation
Attachment: price quotation.rar (contains "price quotation.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-12 06:56:09 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8cf323a5350778bf8c9c96d33a26e5cac9868d85016b0498db62be76056979f8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments