MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 60210ec6a18dd870de0d3b835e349c21b3e50cdcaed78595eb2e771b22c4daf9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 60210ec6a18dd870de0d3b835e349c21b3e50cdcaed78595eb2e771b22c4daf9 |
|---|---|
| SHA3-384 hash: | 356a6c5f9788c342957a6b9acbe4d23b02843d3985188ba0164f98b15d43e827f484fd2f29527371af23012ee3296db9 |
| SHA1 hash: | ef27b29f197f421c9c41e6f767adab8ed732bf47 |
| MD5 hash: | 5b425fe7513881383f2a029ff312624c |
| humanhash: | august-romeo-violet-juliet |
| File name: | 20STMT_2021084411_YONG WANGpdf.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 598'425 bytes |
| First seen: | 2020-08-27 05:42:49 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:Y4Yah9spJ8IEKcB+BMUMxkA0RhW0spJwDZ8aT3gXxJnWrbFYWbV:RYvJ81BgMUMxRuWZniHgXxJn8bFD |
| TLSH | 6FD4234AAF4B198496D4252A797FB78832F1C32177D5C80CEF0D61298ED86D4EF0D923 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: mail.dsecargo.com
Sending IP: 203.242.142.129
From: victim-domain Davy Mao <admin@acct-recon.com>
Subject: RE: Upto AUGUST 2020_STATEMENT / MV. YONG WANG DA 17
Attachment: 20STMT_2021084411_YONG WANGpdf.zip (contains "20STMT_2021084411_YONG WANGpdf.exe")
AgentTesla SMTP exfil server:
mail.vision-architects.net:587
AgentTesla SMTP exfil email address:
hisham.metwally@vision-architects.net
Intelligence
File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-27 05:44:06 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Farheyt
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.