MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6d5702c9d0782ddc59b34bd9cd4b86dd415b8398b1d6f2b48e5c85b666dcd99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d6d5702c9d0782ddc59b34bd9cd4b86dd415b8398b1d6f2b48e5c85b666dcd99
SHA3-384 hash: ce9dc22265440f446bc5411da8bd9d1affd68ba7ecafa3aad8c7501fc6ef97ec3fb8249dbdb42e93e0bba90d9e74ad57
SHA1 hash: fc39e86677a43111317f86c0c8542f6746308bc0
MD5 hash: 7bacfaa4c5e06f3192b59a30866c3ff1
humanhash: nevada-florida-montana-idaho
File name:QOTATION-PDF.rar
Download: download sample
Signature AgentTesla
File size:413'077 bytes
First seen:2020-06-19 06:52:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:d28wfdWgcJb68dsCAraDgz0aI6M5xkU0Ti+:slEA8GCAegTI64xky+
TLSH EF9423DEABB5B2350275AF05A42CF8E4782E5B73DFB99F2906506C211F9E79DB440203
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.eben-ezer.es
Sending IP: 146.255.101.138
From: Sundoz Co., Ltd <Chun@sundoz.com.tw>
Subject: CYTAT.06.19.20
Attachment: QOTATION-PDF.rar (contains "71FaJQ331JCsKhm.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d6d5702c9d0782ddc59b34bd9cd4b86dd415b8398b1d6f2b48e5c85b666dcd99

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments