MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d2f95ac5f807a3387d9d2d905360da84e2f2807e921fcdf7d40c1835f5492d57. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | d2f95ac5f807a3387d9d2d905360da84e2f2807e921fcdf7d40c1835f5492d57 |
|---|---|
| SHA3-384 hash: | 6076d35cfbeef78681b2c2877a0d4fbd11107c2e07ceea37a8e77e99b898827587fdbc9cb21d2a5f965e650d0b71b86b |
| SHA1 hash: | b06902ba7d951faede72b54b6c8baf1296ee9ac3 |
| MD5 hash: | 779811ad83dd2db16880d11d87082cc6 |
| humanhash: | spaghetti-december-happy-diet |
| File name: | RFQ 00288972020.pdf.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 456'137 bytes |
| First seen: | 2020-06-10 06:46:20 UTC |
| Last seen: | 2020-06-10 12:38:30 UTC |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 12288:I73RCVOkwbh2eIrKL/b4Ux73mmRYTmv/4GZxiXXLNfx:k3RAODCuL/FmgGmYYxiXXLD |
| TLSH | 16A4230ED1306105AAAA07711DC929DAB757EF1E04FDB0FC217E8C2E59F5260EA16BD3 |
| Reporter | |
| Tags: | AgentTesla gz |
cocaman
Malicious emailFrom: Nicky Wang <sales@aluminiumsc.com>
Received: from aluminiumsc.com (unknown [78.129.132.154])
Date: 10 Jun 2020 10:17:42 +0100
Subject: REQUEST FOR QUOTATION - TOP URGENT
Attachment: RFQ 00288972020.pdf.gz
Intelligence
File Origin
# of uploads :
3
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-10 06:48:05 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
19 of 31 (61.29%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.