MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 42b4c1f9a68705af6bc80536577058400bdc33f2ae5e878d47a65b4961262483. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 42b4c1f9a68705af6bc80536577058400bdc33f2ae5e878d47a65b4961262483
SHA3-384 hash: 605f07857935e978a122884710a1009d9bc01856aa780dabea52281ff39236cd55168c14462934236a9d5ae446c7f4e3
SHA1 hash: c3ddc00afb41a15ddb9a2209fa94f7d7419de788
MD5 hash: c0366a2bc8acb5f2b689c84840066e5d
humanhash: finch-pip-vermont-beer
File name:INVOICE-CGPHT_#360EA920.Z
Download: download sample
Signature AgentTesla
File size:640'488 bytes
First seen:2020-07-09 20:07:47 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:l0axSu6ufPHOPRC9X1vtUmoC+DOUUawNEgzn/S+Y3a2eeRtzRbher:CwSOf+4VUFPUfegzn/StqHeRv1er
TLSH CBD423608E31872E8B6067B782FF5F4C0F2C98D947761F5676934C676A7D23A6032AC4
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-09 20:09:03 UTC
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 42b4c1f9a68705af6bc80536577058400bdc33f2ae5e878d47a65b4961262483

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments