MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea761a71fb5076b1de1056c62228998d1732acd39a79ab849bacbb8a5cad5c4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ea761a71fb5076b1de1056c62228998d1732acd39a79ab849bacbb8a5cad5c4e
SHA3-384 hash: 93d8a4b2110fe2ab1663dc0dc345ca5a7f00f61d27ef6a2537e6febb52566c659034389c6255d98dc0bf1cd4a0c90b96
SHA1 hash: 689f3fec221e4eea53feb56e89bfa28799a8280b
MD5 hash: 469813d23215da20e955cfe3ebf88c5e
humanhash: nine-equal-music-uncle
File name:Website Inquiry Request for Quote and Distributor Agreement - Caspidelivery LLC SCAN DOCUMENT.rar
Download: download sample
Signature AgentTesla
File size:298'833 bytes
First seen:2020-07-21 08:33:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:3raGZ8dCcBZUe8ftD8ChKJD3bq9LA00rIB3LFb2zUA1+j5Dx0:lZkCmUxFDHhKJD329clrIvA1+j5Dx0
TLSH 995422AFDC9D5516540492DBC4CC51B698856A01CD98244F7CB8BD82EB2F0CAE8BE3CE
Reporter cocaman
Tags:rar


Avatar
cocaman
Malicious email
From: "Candice Owen" <candice@caspidelivery.com>
Received: from box.caspidelivery.com (box.caspidelivery.com [157.245.71.233])
Date: Tue, 21 Jul 2020 00:45:28 -0700
Subject: Website distributor inquiry from denmark
Attachment: Website Inquiry Request for Quote and Distributor Agreement - Caspidelivery LLC SCAN DOCUMENT.rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-21 08:34:07 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar ea761a71fb5076b1de1056c62228998d1732acd39a79ab849bacbb8a5cad5c4e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments