MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4b2ce3d034bfb26ab55a5081f50424435ca0f573ecae253cbd1b089449de7796. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 4b2ce3d034bfb26ab55a5081f50424435ca0f573ecae253cbd1b089449de7796 |
|---|---|
| SHA3-384 hash: | d20d6e975e17699c0920fa333dc1aa3dea91669bf9e603d84d84aa644cfc6b73761c7c09c71f75bc07c4506fdca2a2f9 |
| SHA1 hash: | 6b1b4928df980e1b154473d843653fbaaa2bbf6d |
| MD5 hash: | 82ea147496f0772a62fb3517bce7ee01 |
| humanhash: | april-oscar-carolina-four |
| File name: | Product Inquiry.r00 |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 659'354 bytes |
| First seen: | 2020-08-04 10:17:28 UTC |
| Last seen: | Never |
| File type: | r00 |
| MIME type: | application/x-rar |
| ssdeep | 12288:u7LKeggT3uT9Ts3ngu5mIHFb1qJJkFV50Z9mNu4b6MZoKY82oMGkxAx8cZKSPz:uP32o399FsJJkp0Z9fsxoKuoPkq/z |
| TLSH | 7CE4237ACD9F9BB947FF6500C460A357FABB23945ED2A870CA1DB106CC3B31A5B02605 |
| Reporter | |
| Tags: | AgentTesla r00 |
abuse_ch
Malspam distributing AgentTesla:From: Murat Jasni Hernedas <acb@besqrow.com>
Subject: Product Inquiry
Attachment: Product Inquiry.r00 (contains "Product Inquiry.exe")
AgentTesla SMTP exfil server:
smtp.uae-messefrankfurt.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-04 10:19:06 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.