MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbcfa35f07efe3ef2a64583e6e8c4fdf4b0526eb94dcc7fdf422a377e459f4fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fbcfa35f07efe3ef2a64583e6e8c4fdf4b0526eb94dcc7fdf422a377e459f4fe
SHA3-384 hash: eef00685750c4a94b34f074a0153839252b574c800eef694875113267a39f24505549ff7cff0a0db81af18bddeca8a01
SHA1 hash: 23da66d13c2b1525cbb148adc6731ae405e5d43f
MD5 hash: 872339f81bbb1b70fde356932fb61d65
humanhash: connecticut-harry-washington-quebec
File name:reservationquote.rar
Download: download sample
Signature AgentTesla
File size:897'955 bytes
First seen:2020-06-10 09:57:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:y45Haxvfa+lKwYO7hFMnTEyMIic4HNMhCJZdl:y4kxBDhFFMnTEyEBl
TLSH FF153310CA2536AAED613F6DCBE6418ADD6C22685CA0DB3A64394E43F48DFF3431D6C5
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: cloudserver1.villarambuttri.com
Sending IP: 128.199.93.242
From: Jaap<accountt11112@rbt.co.th>
Subject: Reservation
Attachment: reservationquote.rar (contains "reservationquote.exe")

AgentTesla SMTP exfil server:
mail.panchavatihotels.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.AitInject
Status:
Malicious
First seen:
2020-06-10 09:59:06 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar fbcfa35f07efe3ef2a64583e6e8c4fdf4b0526eb94dcc7fdf422a377e459f4fe

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments