MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be298767ad54766886155cdcfbe7ead13b39e506c629e5c5f7ce5b8a620b1500. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: be298767ad54766886155cdcfbe7ead13b39e506c629e5c5f7ce5b8a620b1500
SHA3-384 hash: 81da6be32759fbfd45a19c32ca16c95d84a6d8d6e3caccc404a368c3a28b4556912c4eb907ae4c7960980b1688d2ecb6
SHA1 hash: 2408954a6e22e9d3d1e00ae26ebc7333eb0b71a2
MD5 hash: 0af486aa70e1c864ae78f11ce3591d01
humanhash: mockingbird-don-cup-mountain
File name:RFQ- DMM-G-FE477-2020.pdf.gz
Download: download sample
Signature AgentTesla
File size:1'940'376 bytes
First seen:2020-05-11 08:28:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:ApCKTwow434A8ize+c0UhQ7nA4cyEEOGm/xjiL+hbLRQwr6ZyxT:XKEZEHL5c0UunA4cyEEO15jiL+JWGT
TLSH 7695339B3D645079EEB0693C10AC2E1D9F5B9C2D4727C0DFBBFE4AC545811683E9C22A
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: fast.kem-p.xyz
Sending IP: 206.189.147.236
From: Trung Nguyen <trung@groupunicell.com>
Subject: URGENT REQUEST FOR QUOTATION;DMM/G-F&E477/2020
Attachment: RFQ- DMM-G-FE477-2020.pdf.gz (contains "RFQ- DMM-G-F&E477-2020.pdf.exe")

AgentTesla SMTP exfil server:
mail.hajartrading.net:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-11 08:36:54 UTC
File Type:
Binary (Archive)
Extracted files:
395
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip be298767ad54766886155cdcfbe7ead13b39e506c629e5c5f7ce5b8a620b1500

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments