MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1674d5a506f4069856dacde9b7110e57a20b2c866e4bcc17e1d74995361903d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c1674d5a506f4069856dacde9b7110e57a20b2c866e4bcc17e1d74995361903d
SHA3-384 hash: 9dfb5413f9015a85556be1c6732458670537592af4b0b8eb09e87fdbd42e379fcd145b9d734a8420a48c1d08bbd49ab0
SHA1 hash: dfbe58387c72cbf51b3c53f67b962646190c710a
MD5 hash: 4dc658b4e551a21ce43d5c37c837ff4a
humanhash: oregon-maryland-three-bakerloo
File name:RFQ-INQUIRY.zip
Download: download sample
Signature AgentTesla
File size:1'106'107 bytes
First seen:2020-05-14 16:17:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:u2TnoGsQHnbGMIj8Qt0HrdxokRj89/lv/ph+SVLLQSahQyvg:u2LoVQHnqtGHrUuc/1xlXQSog
TLSH 38353334FA2D18E9383889154AEB379197E2C73751EE455CEE4D88A0DB6C47D3E81E83
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: sales@nejaatmachine.com
Subject: RFQ-INQUIRY
Attachment: RFQ-INQUIRY.zip (contains "RFQ-INQUIRY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 16:35:47 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip c1674d5a506f4069856dacde9b7110e57a20b2c866e4bcc17e1d74995361903d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments