MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f67fd25abb774d698c8dcb58d42f92ad229c6e1fa102343551f64a79c026e38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3f67fd25abb774d698c8dcb58d42f92ad229c6e1fa102343551f64a79c026e38
SHA3-384 hash: 0e809698dd30b81c008d394855fbe1628499763361a0095990091e2a280ffc9c099d6ac1f0b39d905fb8bdca692894ed
SHA1 hash: ccf76dcf3c97beecf19a36c682cba1ceb9c436a5
MD5 hash: 7a18b32b725f0e284da1124a7f1bdb55
humanhash: emma-charlie-green-failed
File name:URGENT-RFQ.rar
Download: download sample
Signature AgentTesla
File size:1'344'428 bytes
First seen:2020-05-08 12:44:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:aDTh9ypWLPC9Zj7zN1PKUmAKMaH6pJRohgL2O6RypQ92Y3iS3r:aDjEWLi/jdKuJDL/pozh
TLSH 4055339B5145C493E29D2BBE53864A1BB039E82DF0722841D476293C67FD3BDFB69803
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Sales <br5192@bangla.net>
Reply-To: rajshree@cloudconsole.co.in
Subject: TOP SUPPLY// URGENT QUOTATION
Attachment: URGENT-RFQ.rar (contains "MM RFQ.exe")

AgentTesla SMTP exfil server:
smtp.onlinexpertsales.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-05-08 13:35:35 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3f67fd25abb774d698c8dcb58d42f92ad229c6e1fa102343551f64a79c026e38

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments