MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92a0f43be04ce3f5656a84cdaa5b792fe477ad87eac4cd10a542cfb61222069a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92a0f43be04ce3f5656a84cdaa5b792fe477ad87eac4cd10a542cfb61222069a
SHA3-384 hash: 2d97ba881d65e6d5f487e9e0d919cb11cec2cff18a933ca8a78edbd39b6e00d9692ea216d125e033a9bd9cafa9aabc45
SHA1 hash: d42fd7c5b6b8b9d971d2a1d567b6c926e300a8ba
MD5 hash: 3378c8976304ca5fc3ad4641da0533b0
humanhash: five-triple-florida-delta
File name:Contract Agreement.zip
Download: download sample
Signature AgentTesla
File size:327'440 bytes
First seen:2020-07-06 08:23:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:mIVpujsG3H2S0WFNyqB0INjzDN59xLCj+8JpNmtfiCd1tib8aOPebk+c+HXoHgqI:rrudXr0mNvBvFVxL8wiCPG8aOmb8aoVI
TLSH 1F64231B35A236AC43F311C2A485B6B1125EB9F5C305B26902F25BFE369648E741F0DF
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mx.tkb.pl
Sending IP: 89.161.65.153
From: chaitanya <kchaitanya@alphamed.co.in>
Reply-To: jam.marky@yandex.com
Subject: Contract Agreement
Attachment: Contract Agreement.zip (contains "Contract Agreement.exe")

AgentTesla FTP exfil server:
ftp.ciftci.com.tr:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-06 08:24:09 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 92a0f43be04ce3f5656a84cdaa5b792fe477ad87eac4cd10a542cfb61222069a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments