MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbab33fb4dd00ef15e471d016af0089685e1cb99ddef5d4875723754702bbe4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fbab33fb4dd00ef15e471d016af0089685e1cb99ddef5d4875723754702bbe4b
SHA3-384 hash: aafbc7c0aef698370af54340dd2ddd62a9b9bbba61c06e7569e7b719f3022c68ed959291ea8793e6b3e49f49e77b037b
SHA1 hash: 6e90b0f9c517ac0b462fbfbd156e089fc9582606
MD5 hash: d46037a1b1755c0e9d2e4f645598789b
humanhash: wyoming-alabama-bakerloo-skylark
File name:RFQ-URGENT.cab
Download: download sample
Signature AgentTesla
File size:391'541 bytes
First seen:2020-06-04 09:09:02 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:RavMWQtKSAiZYoshE0i6lIjJJtDJyinxYTtzCH3Lk+CXxSmUZ2433+jT5x70pHjR:RavMjZYogE0iSINJhnxq2A+o5Fx8H9
TLSH 2784227AC41ED438B9A566F0A65B0903E0800BD8D70E9F546AC8F854ADF9C377EC8637
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: template.com
Sending IP: 209.58.149.66
From: Taylor Coades <info@template.com>
Subject: New Order- Medikal (URGENT!!!)
Attachment: RFQ-URGENT.cab (contains "RFQ-URGENT.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-04 09:36:40 UTC
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab fbab33fb4dd00ef15e471d016af0089685e1cb99ddef5d4875723754702bbe4b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments