MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7a0f45fa99d04e2446801f74ad61beb975694466b5d06a3445e3dc55a099ee7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: b7a0f45fa99d04e2446801f74ad61beb975694466b5d06a3445e3dc55a099ee7
SHA3-384 hash: 6d9c6b1319d80c8bb2bd6a2c3927e9ec445dd335c2d7d47e6f4dc95d526656e7771fa62daccbeb8b074c250dee83c111
SHA1 hash: 13eda1576882654a3a665008b7d6c0f6314d6417
MD5 hash: 749ab971a6a72e2bd6da0a1ae6f9987b
humanhash: jupiter-queen-magnesium-six
File name:profoma.rar
Download: download sample
Signature AgentTesla
File size:418'849 bytes
First seen:2020-06-25 09:16:59 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:FrcN/QIgw6Hh7zbGPKNpi8zt8ff/RGXthNHBJH0M:FrcyIgwO7zbGPt8ZkG9/HBx
TLSH 2294231E90F6A4C9FFD069BD702C46FB672596C30DCB2623049799B64A78444BFB1F28
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fre.freespirittours.ge
Sending IP: 192.254.140.61
From: executive@freespirittours.net
Subject: profoma
Attachment: profoma.rar (contains "crypt .exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b7a0f45fa99d04e2446801f74ad61beb975694466b5d06a3445e3dc55a099ee7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments