MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abf899ddffe1a31dd8aaaf030713c43774121935d9116c821e12bf41586dcece. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: abf899ddffe1a31dd8aaaf030713c43774121935d9116c821e12bf41586dcece
SHA3-384 hash: ab9de0bc5ce79154fb05ed643e85ba9cfadc177105a694d159535c928e708ab1f674699a81e2c28b8769fb538a649e1c
SHA1 hash: ab8f3a0865a4f4297bf75087910834b45ebf503b
MD5 hash: 5f8a5b2c8fc5c2ac44d67d3d2408799d
humanhash: quiet-echo-juliet-sink
File name:Kimenő számlák.rar
Download: download sample
Signature AgentTesla
File size:434'218 bytes
First seen:2020-07-07 17:28:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:Ar6xSX8DhAi9wq/IBcH2wZvYSa2F9k+uydwva2mbN4uYOnzWX8LQkuyfW:AroDZzIBcPAX2xuyOvYadg/DO
TLSH 8D9423BD015C2A32FD7F3E618E29778B07DAB956614B7EF286121E2C85E38284744E74
Reporter abuse_ch
Tags:AgentTesla geo HUN rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: chla185.avzservicios.es
Sending IP: 185.176.10.68
From: e-szamlazas@fizetesipont.hu
Subject: Kimenő számlák (F-K99134/20) Értesítő
Attachment: Kimenő számlák.rar (contains "invoice.exe")

AgentTesla SMTP exfil server:
mail.serviciocitroen.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-07 17:30:07 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar abf899ddffe1a31dd8aaaf030713c43774121935d9116c821e12bf41586dcece

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments