MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bf16961f77111375f83bab77ffb0eff988cb26b576b682aa0f3d88169502de0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9bf16961f77111375f83bab77ffb0eff988cb26b576b682aa0f3d88169502de0
SHA3-384 hash: 4c1700ca0a05839af8b6739df31b05be463021636ea18acdf339d1fff00eca29aaa4097ba62ea28c41c2a87d031b9701
SHA1 hash: 198ec3029bb5fbcab20cfec13fe4ab4c8c2db144
MD5 hash: 4087bb58ac0a8fac440f00d1985427f1
humanhash: seven-one-princess-zebra
File name:RFQ.cab
Download: download sample
Signature AgentTesla
File size:348'492 bytes
First seen:2020-10-13 12:24:02 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:ZCR5PDGvE/6p3WGju7Rw6em5k73rkBzB77OVzfKBj33N15bWzmzUltj9RES8OFYL:ZCF/+3Fa7R1em5k77aOpy99LWzmzUlt4
TLSH 577423951E3BC24562F26CCF7EE7F987B312C8882C5A505B1F9A6B5B504BC34C1C46BA
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: Sophia Le <sophia.le@sotrans.com.vn>
Subject: QUOTATION
Attachment: RFQ.cab (contains "zec.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-13 12:25:08 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 9bf16961f77111375f83bab77ffb0eff988cb26b576b682aa0f3d88169502de0

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments