MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3be10c9d947a67da8169b343a71d99dc75652ec8ada6c89458102a2f9ec3a5c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d3be10c9d947a67da8169b343a71d99dc75652ec8ada6c89458102a2f9ec3a5c
SHA3-384 hash: e38e0ef955ec12402f9978cbd59292a5101851c53864f899294d8606a1a70f7c3cc8d195f850d3020eeaf21aa98899da
SHA1 hash: 829513ebfc3ca74f47ecb9b437a4802a813f9ce2
MD5 hash: 70d14d4a1a1921970b0632f1722e14d5
humanhash: washington-california-nevada-blossom
File name:Urgent _Quotation.gz
Download: download sample
Signature AgentTesla
File size:769'972 bytes
First seen:2020-11-05 09:22:33 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:LTGLRQgliE8rGrsuP//nDZIOHP5LksaQWZs72Tcr9rrm66+XWIfLLQUDn8FW4Kh7:fGLRQg0duvlHyvZW2wr9raeXWglD8w42
TLSH BBF43304BCD17B58B8F9A9D82FFC25EA4923E24D5FD16DE2832281476A913D93C47E70
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: sky.superhosting.bg
Sending IP: 195.191.149.13
From: Stephanie Snyder <becaye@baconsulting.aero>
Subject: QUOTATION 321879-PRIME MKT
Attachment: Urgent _Quotation.gz (contains "Urgent _Quotation.exe")

AgentTesla SMTP exfil server:
smtp.sirnloop.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.NanoBot
Status:
Malicious
First seen:
2020-11-05 01:13:01 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz d3be10c9d947a67da8169b343a71d99dc75652ec8ada6c89458102a2f9ec3a5c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments