MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 06132fc769ac7a487bb873ccfe40806aa32c692543097cf319b8c3c33481cb9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 06132fc769ac7a487bb873ccfe40806aa32c692543097cf319b8c3c33481cb9b
SHA3-384 hash: 748372565b44f8090bbd16c533228ee69c943a3299f9f19a885f62015dfbe56c0326111a4c9d01f568ae63dfef8ff4d0
SHA1 hash: d9be4d4baa6035d4465e59add93aaa93d92e7af4
MD5 hash: cd3e9b10ff4acb4d4a3d3c3fd074f83d
humanhash: artist-cola-apart-fillet
File name:QUOTE B1018500.pdf.gz
Download: download sample
Signature AgentTesla
File size:712'238 bytes
First seen:2020-09-09 06:47:01 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:rICh7fhhkM50VdiW7tfI+GTe+LeFUiFGPsLI/XwAQYgz3TlBq/vz5VCj:rICh99EiqI+GHLoK9ZMz3q/w
TLSH 2BE433151DCE166A53ACEB87830ABD4F0A5F308445E18DE1E635EEB836BB05347F948B
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: =?UTF-8?B?Um9iZXJ0byBNYXJ0w61uZXo=?= <sales@fengqi.sh.cn>
Received: from fengqi.sh.cn (unknown [45.137.22.76])
Date: 8 Sep 2020 23:43:56 -0700
Subject: *URGENT SUPPLY* QUOTE B1018500
Attachment: QUOTE B1018500.pdf.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-09-09 04:58:36 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 06132fc769ac7a487bb873ccfe40806aa32c692543097cf319b8c3c33481cb9b

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments