MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e212cc51e738afea4dab37eb2328c0625c4b88de107478e675409049da7938a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e212cc51e738afea4dab37eb2328c0625c4b88de107478e675409049da7938a6
SHA3-384 hash: 7ac32697dcadf80e63d38987281965719eff707092584a3b667cea673ccf26d2cfba369ac059f3fefc50089b43353bd5
SHA1 hash: f8d50c7b1678c9e9da378000a75b0971b634e811
MD5 hash: 6e0a5893e8db3c268af04be0e9ec2926
humanhash: winter-moon-robin-speaker
File name:New_Order.rar
Download: download sample
Signature AgentTesla
File size:686'853 bytes
First seen:2020-08-20 17:33:55 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:76vxCoW3+h6A1N7SPTMFuLl64nCCc1mV77rr7H6qo1F7db1S++KCTojmEe6:evxCbe1N27MFuZ6xCV7rr79kNdg++KCK
TLSH FCE423A69BF470FF647DAA2B8B640E617CDC00C0900A6E613AE297691079D3F47FDE41
Reporter cocaman
Tags:AgentTesla rar


Avatar
cocaman
Malicious email
From: Challenge Group Inc <info@challengegroup.com>
Received: from hlmmain2.highlevelmarketing.net (hlmmain2.highlevelmarketing.net [108.168.164.18])
Date: Thu, 20 Aug 2020 13:25:38 -0400
Subject: Request for Quotation
Attachment: New_Order.rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2020-08-20 17:05:05 UTC
File Type:
Binary (Archive)
Extracted files:
26
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar e212cc51e738afea4dab37eb2328c0625c4b88de107478e675409049da7938a6

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments