MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f04e5c0344fb00eff3c1232208afd19ad423ed772f251b5e553bbd80f1eddee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9f04e5c0344fb00eff3c1232208afd19ad423ed772f251b5e553bbd80f1eddee
SHA3-384 hash: 7023a975a68c576dc159b5d85aa27df5bca1fab63164574da7cd9b2956e0798dd528fa8d0b855d4b4bbeeb170eac34ac
SHA1 hash: 2c3e8f096eca35ede0112d2f541bdd77ce4b4c0e
MD5 hash: e3d661ac6402fcb3fda6a3918308a51b
humanhash: lithium-pasta-illinois-winter
File name:COMMERCIAL QUOTATION REQUEST THRUST BORING AND PIPELINE INSTALLATION BID 2000520769.zip
Download: download sample
Signature AgentTesla
File size:358'902 bytes
First seen:2020-05-09 17:50:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:z9j+T8+a2Wf8oYq/0pBAIbuVNZa9w8ZOuPqXUpJY34:zsT8+avf8PCVNEtPMU7YI
TLSH 1B7423A7AF237A31447351DE600506EB7D890CFF13626D2B72992F51AC11F2E6BC6427
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: centos-s-1vcpu-2gb-fra1-01.local
Sending IP: 165.22.27.150
From: Benoy Vattappilly <benoy.vattappilly@saipem.com>
Reply-To: Benoy Vattappilly <mog_b@mail.ru>
Subject: REQUEST FOR TECHNICAL / UNPRICED COMMERCIAL & COMMERCIAL (ENCRYPTED) QUOTATION - PR 11657509 THRUST BORING AND PIPELINE INSTALLATIO
Attachment: COMMERCIAL QUOTATION REQUEST THRUST BORING AND PIPELINE INSTALLATION BID 2000520769.zip (contains "COMMERCIAL QUOTATION THRUST BORING AND PIPELINE INSTALLATION BID 2000520769.exe")

AgentTesla SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-09 18:35:26 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9f04e5c0344fb00eff3c1232208afd19ad423ed772f251b5e553bbd80f1eddee

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments