MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a82e42a105d23c62d8245566c295b87024f6416b03c20834095ad98b2b75316. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3a82e42a105d23c62d8245566c295b87024f6416b03c20834095ad98b2b75316
SHA3-384 hash: 2c80635f4c369f8c732db91cd37bd6f5834d210164c2d19a4445f38ccf7f8ebaa76002d2dc071713668ea69cddf6f890
SHA1 hash: fb8f9626a72d14e53e4abf782047dea0ef73bb7a
MD5 hash: 922b60e62a8b2facb9554a5ff7ed927c
humanhash: thirteen-charlie-bacon-nuts
File name:Inquiry.rar
Download: download sample
Signature AgentTesla
File size:90'282 bytes
First seen:2020-10-05 11:15:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:U1g/jPzdD7ycCwm0u3ZvYgSX0SnBZ0KkR8nyIag9+z7+7Ehg4/Mvqju3sPCn3jUN:bk7F0u37SXJzkGnyIaOyCwhgMMvO2sP5
TLSH 22930297CD91EF96C0989C08161FB57FEC54E0F07DC6159F82B05DA32B9B68D021D8AA
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.com
Sending IP: 199.115.195.109
From: Mr. Kim Sung Hae<office-procurement@mail.com>
Subject: Product Inquiry
Attachment: Inquiry.rar (contains "Inquiry.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.DarkStealer
Status:
Malicious
First seen:
2020-10-05 10:31:07 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3a82e42a105d23c62d8245566c295b87024f6416b03c20834095ad98b2b75316

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments