MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f6f308ccca31b560925ad4624d197f65cb71fef3586c89f44a48bd1a7cb109cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f6f308ccca31b560925ad4624d197f65cb71fef3586c89f44a48bd1a7cb109cb
SHA3-384 hash: a6c6e2cccf6c87f0ef82f5b9e4ae2e17c13246d2e5ecf7e77ffef78aa5bcf55cfe8d68284c779bb7fd33e0a7844bad3a
SHA1 hash: ffcb3cdf6e4a52e64c9494f6ba6286ac3afc4f65
MD5 hash: d3cabf31235333be817b7136a362d3e0
humanhash: violet-december-zebra-oxygen
File name:RFQ ORDER 002267.IMG
Download: download sample
Signature AgentTesla
File size:1'376'256 bytes
First seen:2020-07-06 14:51:35 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:1Z7GXbYoWBPb0B+Thxy2B7Sb4fyhfHD7JYEAiPpRwPihb3TfYXA:XSRWJpTm2obqoRPwDw
TLSH 14559E52F2D00833D16B267C8D1B576CA935BE113A28D9467BF81C4CAFF969334292E7
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.strongmailvault.com
Sending IP: 111.90.144.79
From: Yonzhi Tan <info@intaol.com>
Subject: RFQ ORDER 002267
Attachment: RFQ ORDER 002267.IMG (contains "RFQ ORDER 002267.exe")

AgentTesla SMTP exfil server:
smtp.ay0ub-sd.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DelfFareIt
Status:
Malicious
First seen:
2020-07-06 14:53:05 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img f6f308ccca31b560925ad4624d197f65cb71fef3586c89f44a48bd1a7cb109cb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments