MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8026e76704792aab1586113149c760f4bf230b63fff4061bc1c12a635f62119. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a8026e76704792aab1586113149c760f4bf230b63fff4061bc1c12a635f62119
SHA3-384 hash: 7ce3717f542941de0fdce3d6ddb5cf45a1d5a14a4d208fedbcfbbcc2246485d22e8b86986b6e364978b3a916714a51b8
SHA1 hash: 6e213e556acae036adc4076e9d2858fc2ae5abe0
MD5 hash: f14b17b81a0bbe4b4786bac1185f6ab9
humanhash: rugby-jig-thirteen-violet
File name:Insignia RFQ.7z
Download: download sample
Signature AgentTesla
File size:689'163 bytes
First seen:2020-08-04 09:23:07 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:Z+4ygOdy5WB+nq04Wlsq4d6xBWVl/buJTkyoZin6MWYSC3/tCNILtIs6XXPSoYMy:Z4FwWUqf16xB+/bX+n6MvtIIxt6XX6oG
TLSH 01E4335EDE247D1F61DE4A1E080812632B0699021C495E686C7FFE6393B9DB092B73F6
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: msvfabrics.in
Sending IP: 81.171.9.147
From: Gary Simona <manoj@msvfabrics.in>
Subject: Request for urgent quotation for insignia project
Attachment: Insignia RFQ.7z (contains "XIMGOMscqQ1PB6V.exe")

AgentTesla SMTP exfil server:
smtp.lettu.us:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.NanoBot
Status:
Malicious
First seen:
2020-08-04 09:25:05 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z a8026e76704792aab1586113149c760f4bf230b63fff4061bc1c12a635f62119

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments