MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e9fd79bc398203e7c54a28fce2cd7cac4f491898ceaf5a7dd6925ec7609fe26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6e9fd79bc398203e7c54a28fce2cd7cac4f491898ceaf5a7dd6925ec7609fe26
SHA3-384 hash: a621a5d4c3da5b0dac9e65d0e0f0dc848bbb110418acd3d4898375db4f8d1b77b7fde58773abfc91aba6182cd7979495
SHA1 hash: f87651ed3febb1ccaf7000cc8b0d8a1e7469147d
MD5 hash: 57960a4ffbeb222f6feb266c782ba7ed
humanhash: wisconsin-wyoming-burger-ten
File name:Valve Inquiry Order.rar
Download: download sample
Signature AgentTesla
File size:461'863 bytes
First seen:2020-06-21 07:26:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:KO+uxwnGAfO2QKRtlb7U+7o6Ws5uSvHdCk1nc4:KZuxNAmtKRtJx7o6pv9jl
TLSH 00A423F864767DACE249C3DB94BF652111CBC100ED5A96EC7DF984909AF2C21B481BB3
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: "狄志明" <dizhiming@weltpack.com>
Subject: Quotation Valves & flanges and fittings
Attachment: Valve Inquiry Order.rar (contains "Valve Inquiry Order.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.BitStealer
Status:
Malicious
First seen:
2020-06-19 11:22:45 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 6e9fd79bc398203e7c54a28fce2cd7cac4f491898ceaf5a7dd6925ec7609fe26

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments