MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c361dec4215409ab73ee7b8d9672378f05c4da2f7467c797d8e615c8773e24de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c361dec4215409ab73ee7b8d9672378f05c4da2f7467c797d8e615c8773e24de
SHA3-384 hash: 857227dc4bee83bafffb4f428cfd9d4dbb59a9a0f16f9753d00dd007f3fd77297f2a868ca3a8a4b5bf73b1dcd4c7d363
SHA1 hash: 6aa3a55221644a7881b9459c86cb1219fd96c6a2
MD5 hash: 78d55bf26b0fc3fee3cf7d29e82e90f2
humanhash: kansas-earth-lemon-friend
File name:RFQ Q-80079 (Q-20-28) - Level.gz
Download: download sample
Signature AgentTesla
File size:361'955 bytes
First seen:2020-07-24 05:48:40 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:2SIys58ZZmMbfq60aRZOhVp81EfRZw4bRks6b5vcE4etcZG2ljNxxor:2SHs58TmMr/0aO/p3RZw4NP61vcE4k0k
TLSH DA74239A73A38F2EB49951B97DDBC8546E8C3DBD07C0A35076152EEA5DD0C4237BA088
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: MIDDLE EAST OILFIELD SERVICES LLC <admin@sakurarubber.com>
Received: from sakurarubber.com (unknown [37.48.85.197])
Date: 24 Jul 2020 05:42:00 -0700
Subject: OMI/EN-FAB, Inc. RFQ Q-80079 (Q-20-28) - Level (DP) Transmitters/Displacer Level Transmitters - PDO Bidding
Attachment: RFQ Q-80079 (Q-20-28) - Level.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-24 05:50:07 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz c361dec4215409ab73ee7b8d9672378f05c4da2f7467c797d8e615c8773e24de

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments