MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e78f2342dbacebef772c2a8d775abe436fc3b7501f7019939e9b9fd3e3eced40. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e78f2342dbacebef772c2a8d775abe436fc3b7501f7019939e9b9fd3e3eced40
SHA3-384 hash: 1183e43e58b75583b588038ba73a736166100a2368b6a582ac1be2c4c278064ef8211c6bc7449bb70b53bf6870964f7c
SHA1 hash: bcd6c0c4e3833fbb43556a2d8912341d4acd249b
MD5 hash: 51a3fdec12808c18612726e430b9d005
humanhash: lion-connecticut-pennsylvania-venus
File name:RFQEX50GO_pdf.img
Download: download sample
Signature AgentTesla
File size:1'835'008 bytes
First seen:2021-04-05 06:33:03 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:1a8169VIVvHn9dY8rD7b6s5FT/AOwdSf/aQkeDAnTMBfEcyiYyjcaWVT5rzjxJ+e:n16IVvHnbYQPJFLAyfkHQCqjcaWVzU
TLSH C5859BD1EE43D244D85A1AF0D42FC25D5662FF082F2DED09698CF3081A72A9ECAD56F1
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.serversendmail.live
Sending IP: 77.83.172.183
From: pro@serversendmail.live
Subject: RFQ
Attachment: RFQEX50GO_pdf.img (contains "RFQ#EX50GO_pdf.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2021-04-05 05:34:43 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img e78f2342dbacebef772c2a8d775abe436fc3b7501f7019939e9b9fd3e3eced40

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments