MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8f349423609a0ba6ac722d59a263044d1ee5403ae8a32011e9a7f88ca4a4918. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d8f349423609a0ba6ac722d59a263044d1ee5403ae8a32011e9a7f88ca4a4918
SHA3-384 hash: a4209655934685bc2a8c1f013edfe5661bff00a64601b80386fa10877871c0c57fd79d74e3ac47bdc4924420c38f04b2
SHA1 hash: a2e7009a381a68243f838b08c5f4f87058f1a9f5
MD5 hash: 8dec50ca2059cfc09047773e73e4befe
humanhash: angel-montana-magazine-ohio
File name:RFQ-August.rar
Download: download sample
Signature AgentTesla
File size:545'923 bytes
First seen:2020-08-10 13:03:46 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:MQyg6jK4Ng76zjwO+079/gU5AnZINXWHhRu4sDW/PXSLMMR4Mio:MQB0CbuerrWLtx
TLSH 72C4232015FBD6ABE4A18704C867B0EAF539BB1D73325F950A83BB1796C295081FC9C7
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vs1.backuplider.com
Sending IP: 212.129.3.18
From: Jenifer Pinket <web@imap.cat>
Subject: Order Specification
Attachment: RFQ-August.rar (contains "RFQ-August.exe")

AgentTesla SMTP exfil server:
smtp.ola4tai.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-10 13:05:05 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar d8f349423609a0ba6ac722d59a263044d1ee5403ae8a32011e9a7f88ca4a4918

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments