MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7fc055ec3ee88d19617d8558c822d7b6a60e80b85666f06b9a97fbb325dfc30. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d7fc055ec3ee88d19617d8558c822d7b6a60e80b85666f06b9a97fbb325dfc30
SHA3-384 hash: 9355f658a6cdccb9afcd4cf005f3720b45967d276d2330a02a06ad60e51999de0c0dbf29c6f3b2655feb480a0131c6e0
SHA1 hash: e41da684108de395ab5ece7ff27ec256852e5619
MD5 hash: 089252386c4f45d30b51afb0be7a25b4
humanhash: alpha-glucose-india-lemon
File name:Cabot Oil Gas Corporation.zip
Download: download sample
Signature AgentTesla
File size:978'997 bytes
First seen:2020-12-20 07:56:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:49h5L59ipo4P+ifoOS3Dacz0AcCcXsQ6SPlHRB1tPy:65khlQZN4lCcX76SPVy
TLSH 632533FD8B02A3B2067B01E1FE67D324695BB9E15CBE54399A40692D454C23F2EFD123
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.dsfabricsllc.com
Sending IP: 198.255.55.42
From: Dan O. Dinges <george.stark@cabotog.com>
Reply-To: k1@ecg-ingenieria.mx
Subject: Cabot Oil & Gas Corporation / Request For Tender
Attachment: Cabot Oil Gas Corporation.zip (contains "Cabot Oil & Gas Corporation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
203
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-19 01:44:10 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d7fc055ec3ee88d19617d8558c822d7b6a60e80b85666f06b9a97fbb325dfc30

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments