MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7259f8e83abe7c8ff9f233b2d5c05f1d1acfb67127cf92b3306190ad3c10fac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f7259f8e83abe7c8ff9f233b2d5c05f1d1acfb67127cf92b3306190ad3c10fac
SHA3-384 hash: c6dd413895f2c618cfd91844247ec8469430ca2f79a315a52ec752d4ac400cf19a300c8021ced142bce222db0d2e20e6
SHA1 hash: 556c9b2f74bffb8660543b2fbef4c2cd79b9227c
MD5 hash: c7d7977354eb2564971c00f935c42a58
humanhash: shade-yellow-high-nebraska
File name:Quote_3076854.pdf.r00
Download: download sample
Signature AgentTesla
File size:402'797 bytes
First seen:2020-04-29 17:26:39 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:TitxbM3bbCnHAmVcgETg9KrL2k8obtc4pYDxJbCrrWmLvfsacScS0HDavEh:TiHebbC1LKbZpYDyJEacSCmv6
TLSH A88423C05D6C41C9A4F30C0C1EB79ED7142E66A3D7A7828BA62843FCE279916ED0DF65
Reporter abuse_ch
Tags:AgentTesla r00


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: bioboonbiotech.com
Sending IP: 212.32.245.155
From: Medlab<info@bioboonbiotech.com>
Subject: Request For Quotation
Attachment: Quote_3076854.pdf.r00 (contains "Quote_3076854.pdf.exe")

AgentTesla SMTP exfil server:
us2.smtp.mailhostbox.com:587 (208.91.199.224)

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Frs
Status:
Malicious
First seen:
2020-04-29 17:35:42 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 f7259f8e83abe7c8ff9f233b2d5c05f1d1acfb67127cf92b3306190ad3c10fac

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments