MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27fcab0d42fd182772b088b02fa0fb3cc52e7f30c9a8fee9756c2245d63f12bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 27fcab0d42fd182772b088b02fa0fb3cc52e7f30c9a8fee9756c2245d63f12bf
SHA3-384 hash: fab5adaba19771fa18222b9b742d375b12b0deea498110c20dab3c6efbfd50d8c3dcbaefa8879ee76ff985aa76fdcdcf
SHA1 hash: c259ceb45b1071f5ba3d0e549aeddf3a62aa3992
MD5 hash: 5a828f6b893e69c85b9d485ad2385dd7
humanhash: yellow-potato-spring-edward
File name:Revised PO 453924.arj
Download: download sample
Signature AgentTesla
File size:491'412 bytes
First seen:2020-07-07 09:44:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:+Ep9OW+wleSaJsVkYZlzRoxJ4w2c1YdxDsY4nkbstg9JEifvMUyWL8tLVmqNUx5i:jp9OW+3SaJs6wjos6le9JJMpzju4rKsp
TLSH 9DA423C936950931FFBB63783F2D4DB4CA488B49DA9130E6475924BEAC856907DE30EC
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.lemcon-asia.com
Sending IP: 209.182.203.225
From: Trang <info@kienhang.com.vn>
Subject: DSA-KH: Revised PO# 453924, C# 3566
Attachment: Revised PO 453924.arj (contains "Revised PO# 453924.exe")

AgentTesla SMTP exfil server:
smtp.hk-gruop-sg.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-07 09:46:06 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 27fcab0d42fd182772b088b02fa0fb3cc52e7f30c9a8fee9756c2245d63f12bf

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments