MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bdc7542054db176843dc80f52316fe4961254ed557bd3e9afc5a4711b2cd370. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5bdc7542054db176843dc80f52316fe4961254ed557bd3e9afc5a4711b2cd370
SHA3-384 hash: bfc80780e4718ae60d1661e7e4c926f7318e6cd3f33f907aabd077a315eddd1e92864b765db0363d5021ace6b81d0049
SHA1 hash: 936db2101b7e15273600d6f899a756cc3b16347b
MD5 hash: 5fe083b626c6341f3670054ea21f119e
humanhash: enemy-music-cold-comet
File name:Quote.zip
Download: download sample
Signature AgentTesla
File size:477'003 bytes
First seen:2020-11-07 10:17:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:GsohSdAfRWRF0mDgkuX5yWL0uI+I6IUHwv+OmUnjrOFJxLYsLRVfw3jcBPfhGBBx:GsocQCYkuX5lb3IKwWys8Qfho
TLSH C3A42301EDDFCEC4E96993802DC39D9C6515020AB5528830CE8BF74F6E9F6C37E59A62
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: iflytek.com
Sending IP: 36.7.172.15
From: 储佳佳 <jjchu3@iflytek.com>
Subject: QUOTE USD PRICED FOR ATTACHED
Attachment: Quote.zip (contains "Quote.exe")

AgentTesla SMTP exfil server:
server266.web-hosting.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2020-11-06 22:00:25 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5bdc7542054db176843dc80f52316fe4961254ed557bd3e9afc5a4711b2cd370

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments