MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0bc1bc3f8dc0e1b220fc7d98de8cbef48023a8a71128d057f5da6dddc816946. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f0bc1bc3f8dc0e1b220fc7d98de8cbef48023a8a71128d057f5da6dddc816946
SHA3-384 hash: e74716647a5bb6a04361c276ce8291cb2b0ef878c02df343650a57cbb75fcecbd98f4b3511ec2b621d703812bed146a7
SHA1 hash: 78c945354db6b54f576f6a9335f6fdfa8039c210
MD5 hash: 1b48f6979dd2ff000a96ef6568ba7a3f
humanhash: orange-king-bakerloo-comet
File name:QUOTATION.LZH
Download: download sample
Signature AgentTesla
File size:363'825 bytes
First seen:2020-06-08 19:13:40 UTC
Last seen:2020-06-09 05:46:35 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:WbIdmSiSBPyv7cGyZdG3Rw0LJNWeg18V2KIwpcsH29Dh2atG9FnWQuDD8tT2kTNW:yIAAqWX/0LJUMRpDkIX+uM1
TLSH AD7423A391C16D3A7092EAD6598236E97CC69FA0D441420DB02D0E8A3FB9B5F1D35F1B
Reporter abuse_ch
Tags:AgentTesla lzh


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slok.com
Sending IP: 156.96.47.116
From: Slok Inc<procurement@slok.com>
Reply-To: fra_white33@yahoo.com
Subject: QUOTATION
Attachment: QUOTATION.LZH (contains "QUOTATION.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-08 19:15:09 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar f0bc1bc3f8dc0e1b220fc7d98de8cbef48023a8a71128d057f5da6dddc816946

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments