MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d8f349423609a0ba6ac722d59a263044d1ee5403ae8a32011e9a7f88ca4a4918. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | d8f349423609a0ba6ac722d59a263044d1ee5403ae8a32011e9a7f88ca4a4918 |
|---|---|
| SHA3-384 hash: | a4209655934685bc2a8c1f013edfe5661bff00a64601b80386fa10877871c0c57fd79d74e3ac47bdc4924420c38f04b2 |
| SHA1 hash: | a2e7009a381a68243f838b08c5f4f87058f1a9f5 |
| MD5 hash: | 8dec50ca2059cfc09047773e73e4befe |
| humanhash: | angel-montana-magazine-ohio |
| File name: | RFQ-August.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 545'923 bytes |
| First seen: | 2020-08-10 13:03:46 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:MQyg6jK4Ng76zjwO+079/gU5AnZINXWHhRu4sDW/PXSLMMR4Mio:MQB0CbuerrWLtx |
| TLSH | 72C4232015FBD6ABE4A18704C867B0EAF539BB1D73325F950A83BB1796C295081FC9C7 |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: vs1.backuplider.com
Sending IP: 212.129.3.18
From: Jenifer Pinket <web@imap.cat>
Subject: Order Specification
Attachment: RFQ-August.rar (contains "RFQ-August.exe")
AgentTesla SMTP exfil server:
smtp.ola4tai.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-10 13:05:05 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.