MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d2f95ac5f807a3387d9d2d905360da84e2f2807e921fcdf7d40c1835f5492d57. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d2f95ac5f807a3387d9d2d905360da84e2f2807e921fcdf7d40c1835f5492d57
SHA3-384 hash: 6076d35cfbeef78681b2c2877a0d4fbd11107c2e07ceea37a8e77e99b898827587fdbc9cb21d2a5f965e650d0b71b86b
SHA1 hash: b06902ba7d951faede72b54b6c8baf1296ee9ac3
MD5 hash: 779811ad83dd2db16880d11d87082cc6
humanhash: spaghetti-december-happy-diet
File name:RFQ 00288972020.pdf.gz
Download: download sample
Signature AgentTesla
File size:456'137 bytes
First seen:2020-06-10 06:46:20 UTC
Last seen:2020-06-10 12:38:30 UTC
File type: gz
MIME type:application/x-rar
ssdeep 12288:I73RCVOkwbh2eIrKL/b4Ux73mmRYTmv/4GZxiXXLNfx:k3RAODCuL/FmgGmYYxiXXLD
TLSH 16A4230ED1306105AAAA07711DC929DAB757EF1E04FDB0FC217E8C2E59F5260EA16BD3
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: Nicky Wang <sales@aluminiumsc.com>
Received: from aluminiumsc.com (unknown [78.129.132.154])
Date: 10 Jun 2020 10:17:42 +0100
Subject: REQUEST FOR QUOTATION - TOP URGENT
Attachment: RFQ 00288972020.pdf.gz

Intelligence


File Origin
# of uploads :
3
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-10 06:48:05 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz d2f95ac5f807a3387d9d2d905360da84e2f2807e921fcdf7d40c1835f5492d57

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments