MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a67f3429d993c80b0a9c67ef5b4755befebc5696d767adf939890890c13e8dd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a67f3429d993c80b0a9c67ef5b4755befebc5696d767adf939890890c13e8dd6
SHA3-384 hash: 508454229a59810be800a4351e0a0b50079f7e7df72691efd097fe0816397b379cfbe6750ed9578270e627ca7957891e
SHA1 hash: effa18a7bfca2a92cc9dd3bc7e12028462f89ee9
MD5 hash: 6d411ce98ea8a51c8175be354637f24b
humanhash: fourteen-utah-iowa-mirror
File name:Request for Quote RFQ365432- MSA.zip
Download: download sample
Signature AgentTesla
File size:1'014'533 bytes
First seen:2020-05-27 18:16:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:Il1t0T77bkl8gQic3eAOSTRHjBD9hy9tQCeFR5lg:eWuiiTAFJy9GR5u
TLSH D92533CAA2AD89D9EF6A344BA57385AF1888619F7E0C04DD35BF6001453E8734ED05AF
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: bk.ru
Sending IP: 62.113.215.251
From: Sukhveer Singh Nandu<mikhailivan.wire@bk.ru>
Reply-To: Sukhveer Singh Nandu<qmi19@bk.ru>.
Subject: Request for Quote: RFQ#365432- MSA
Attachment: Request for Quote RFQ365432- MSA.zip (contains "Request for Quote RFQ#365432- MSA.exe")

AgentTesla SMTP exfil server:
twire.icu:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 18:37:37 UTC
AV detection:
27 of 48 (56.25%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a67f3429d993c80b0a9c67ef5b4755befebc5696d767adf939890890c13e8dd6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments