MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abb7d40d443544f4df04df3aad291f636b0ff1492d318e0d34be9d56e3157e0b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: abb7d40d443544f4df04df3aad291f636b0ff1492d318e0d34be9d56e3157e0b
SHA3-384 hash: c5c0ccc6c754f736aca21da8ed126b550fca63cd5774d96017118171fefe75f55c35636ba3e3cd65a25802ee85c366a0
SHA1 hash: 6171106671e0b76ef89834a2e4ea57c7ddd39f6b
MD5 hash: ed473096e9861d9a779e72633baf1df3
humanhash: alpha-single-fifteen-seven
File name:RFQ.pdf.z
Download: download sample
Signature AgentTesla
File size:482'182 bytes
First seen:2020-07-15 07:46:07 UTC
Last seen:2020-07-16 05:26:38 UTC
File type: z
MIME type:application/x-rar
ssdeep 6144:Hpo7/9aT+ZGN09bHonXHHHIvkN+0fx36mC98hNvP2ASKpNeZz4/W2v0AoDI:Hy1arQInXHaEzC9I2FaNCz2GvDI
TLSH A9A423C984F455F7A02CDFA228DFCB8A8E15462C0B086349BD5E2C635753778ABED64C
Reporter cocaman
Tags:AgentTesla z


Avatar
cocaman
Malicious email
From: Export Department<Muhammad@safholland.com>
Received: from safholland.com (unknown [37.48.85.246])
Date: 15 Jul 2020 06:27:39 -0700
Subject: RFQ (URGENT)
Attachment: RFQ.pdf.z

Intelligence


File Origin
# of uploads :
3
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-15 07:48:06 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
16 of 29 (55.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z abb7d40d443544f4df04df3aad291f636b0ff1492d318e0d34be9d56e3157e0b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments