MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 965cf1859f4aac2a1ae8c83da2a142754516ed87848e24d13df803e97f36bd6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 965cf1859f4aac2a1ae8c83da2a142754516ed87848e24d13df803e97f36bd6c |
|---|---|
| SHA3-384 hash: | 70ff5e9e6ea60df7ce245174eec01478ded98cbdc43dcd49f7741e2bc8a5fd74bcabbc9a45b283a1ce6ac59f4f716f9d |
| SHA1 hash: | 5ba52bbccac9bea7d6e4b0cf37f57af0b59e0eed |
| MD5 hash: | e9fdb14e53370e8c23ef1ca81d715224 |
| humanhash: | victor-diet-single-quiet |
| File name: | AMTEC INC. 2020 Order ~ RFQ.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'376'256 bytes |
| First seen: | 2020-08-14 14:56:42 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 24576:Y7vqbZzuihDozTmUfzLIiDZ8nSmm2BYfv:Y7vo1olt8pBBYH |
| TLSH | 5D55AE62A2E04B37C1A7163F9C7B87A4E839FE5DEA2459472BF71C4C5F392803426197 |
| Reporter | |
| Tags: | AgentTesla img |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.sekawan.com
Sending IP: 45.251.72.199
From: Shaikh Jaffar <055077@sekawan.com>
Subject: RE: AMTEC INC. 2020 Order/RFQ
Attachment: AMTEC INC. 2020 Order ~ RFQ.img (contains "filesss.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-14 14:58:10 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.