MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 096bf4057b8392cbc1cc165841df502c8356f90ba50795ac2f5c14d6c65bc62b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 096bf4057b8392cbc1cc165841df502c8356f90ba50795ac2f5c14d6c65bc62b |
|---|---|
| SHA3-384 hash: | cc4d0a0274d34f81a15bee5612a24640b06efc3d6157e0b37d66616a4965875a0ef52b8d98e3da19673cb000236cb5f7 |
| SHA1 hash: | 51b6a610b351569087c766d5e26defa8499a9fa5 |
| MD5 hash: | d696d4d380bc1a9742329eb76b30b9a2 |
| humanhash: | delta-october-romeo-september |
| File name: | swift copt_pdf.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 426'030 bytes |
| First seen: | 2020-07-20 09:55:46 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:73O5sptY1jU9IJxyebYDib0NcYFAikKkiX:gsptYo9IJvYD+Hv5iX |
| TLSH | 6194238674ED5B46B914605F737FAB02940A95E438F29C4AB1932F738A14E097C14BFF |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:HELO: mm0.825.biniomunidos.gq
Sending IP: 161.35.205.5
From: Accounts Dept. <noreply@825.biniomunidos.gq>
Subject: Fwd: Re: Payment Advice 20/07/2020- Advice Ref:[SWFA31093538] / ACH credits / Customer Ref:[HX985310810741] / Second Party Ref:[24]
Attachment: swift copt_pdf.gz (contains "gunzipped")
AgentTesla SMTP exfil server:
smtp.elittacop.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-20 09:57:04 UTC
AV detection:
27 of 48 (56.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Unknown
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.