MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96e53e51f350bdd5c7ad5e580f96869bcdb000a30eaaf134605685bb953a13d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 96e53e51f350bdd5c7ad5e580f96869bcdb000a30eaaf134605685bb953a13d8
SHA3-384 hash: ce0c65927243cc429a90ffda1a2ac036a153149eb877ead41acf5cf2f3d80e4c2578374e1b4db947ad1bfe84496c89c6
SHA1 hash: f0c5e3c8f62575e35cdb74bdf9074d14021ce640
MD5 hash: 702f838001de25e7b6cd22b27ea2fa23
humanhash: sweet-uranus-salami-juliet
File name:PO.gz
Download: download sample
Signature AgentTesla
File size:476'162 bytes
First seen:2020-07-10 13:25:29 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:9wQu0mis9ikW8TL23m89jOSw4sDeoXUTViTbk/KcOcVuXhY/UWxdDMb3trgibMkW:9wB68T38nw45UUYX2nDMZgYMkW
TLSH 67A42313A5896672DEA7CDB0AFA0EE0055752FC8F440B065168F97F61CC033DAABED64
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: Nils Kraemer <nils.kraemer@bplogistics.de>
Received: from bplogistics.de (unknown [95.211.211.232])
Date: 10 Jul 2020 21:06:48 +0800
Subject: RE: NEW PO345678
Attachment: PO.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-10 10:56:57 UTC
File Type:
Binary (Archive)
Extracted files:
39
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 96e53e51f350bdd5c7ad5e580f96869bcdb000a30eaaf134605685bb953a13d8

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments