MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8943183fd8a7489134ac8161c805476f47cf68695f21b9bb0d3971e0d622a2b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8943183fd8a7489134ac8161c805476f47cf68695f21b9bb0d3971e0d622a2b7
SHA3-384 hash: 82bce93d59369fa20455c8958074e432d6bc6a10744e9a8902db0d8e30f91922af8e8727c1de80f53b58cbea921585b7
SHA1 hash: 583dca6f5827f45470f878b5809a711bdfa1d701
MD5 hash: faff970b0b100fa3733a9197956aa470
humanhash: football-nitrogen-william-fillet
File name:AD1-2001028L PL.gz
Download: download sample
Signature AgentTesla
File size:407'785 bytes
First seen:2020-08-05 07:26:20 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:6EVSB5e7JO1RQ7EyxX744DQKmwkh44++kFaTA8X/H2ax0u+6SmKnSlN/WzO0h:6le7SEX04DeX1+JFaTd/bt+6SBSn/IOs
TLSH 2684231C378F3A86B62C21C4634BADAE5C859B09BCAF4165FB4C34CDD957087EB18A47
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: uzlinshpl01.uzcloud.uz
Sending IP: 185.74.4.8
From: Michael han <sales12@ceaworld.com>
Subject: AW: Invoice For Shipment
Attachment: AD1-2001028L PL.gz (contains "AD1-2001028L PL.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-05 07:28:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 8943183fd8a7489134ac8161c805476f47cf68695f21b9bb0d3971e0d622a2b7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments