MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 248f158d0be4760bb64740a7c5d73b21502fd6e177f6a9cb543fcf92c27f43d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 248f158d0be4760bb64740a7c5d73b21502fd6e177f6a9cb543fcf92c27f43d3
SHA3-384 hash: 4ec784e9c5ffdffa1d5eca1e9769bce5a7018598a5698538a7f2df046bf5bfb53f57cb9d7b85180e5e1240829900591f
SHA1 hash: 529f9a4b2cf9b2256013893afc39a9d4f7373d7a
MD5 hash: e73e473d95849ac73bdeb86c84014a25
humanhash: october-california-papa-bulldog
File name:new_PO.zip
Download: download sample
Signature AgentTesla
File size:406'777 bytes
First seen:2020-06-16 05:45:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:vKYhsKhridZ/fD+hrliS1ylU+FVrygu2Td/8fXH:vKYr8axlt1sbFlHu2TdG
TLSH 13842318DBF5E51A65962EEFE002F36E3351B25F718B5E8D649FF403C516BC0BA60029
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: asmtp225.fastnet.ch
Sending IP: 193.246.63.225
From: revillard <revillard@rezo.ch>
Subject: NEW ORDER LIST.
Attachment: new_PO.zip (contains "new_PO.exe")

AgentTesla SMTP exfil server:
mail.ab-care.eu:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-16 05:47:03 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 248f158d0be4760bb64740a7c5d73b21502fd6e177f6a9cb543fcf92c27f43d3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments