MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9765a23ed91fb926ea7c9806f285b7b0af59f00ce8c34f663f0602438acf7acb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9765a23ed91fb926ea7c9806f285b7b0af59f00ce8c34f663f0602438acf7acb
SHA3-384 hash: 28aed553615a206e226b31e8555bf3887aee65384a1b7fb8d520f91ed66e4678cc433a6ad8f6a4150a442f1bd55a4a42
SHA1 hash: 446630413aaf89e86b74fad9aa2fb4a08285e208
MD5 hash: 4c00521f670b93cbd17725112030fb21
humanhash: earth-leopard-arizona-mirror
File name:quotation.rar
Download: download sample
Signature AgentTesla
File size:616'395 bytes
First seen:2020-12-13 17:14:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:Pp+HsBsy89yQg7Q2hiAemQEAGcrL/RRXA8TXdJEeTWEitii:Pp+fk8AemQ9zLbXAgEeTWEiv
TLSH 6FD4231F1C87401FC84D261608DD2619A27E5FEEDB2E77F0B8A28D51A9ABD3D132F425
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: iqum.mx
Sending IP: 67.227.222.135
From: Info<contacto@iqum.mx>
Subject: request for quotation.
Attachment: quotation.rar (contains "quotation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
222
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 9765a23ed91fb926ea7c9806f285b7b0af59f00ce8c34f663f0602438acf7acb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments