MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b45f861c30587affe7bb511db60eab13d2f848ffffd56e4fb04c8137395caeba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b45f861c30587affe7bb511db60eab13d2f848ffffd56e4fb04c8137395caeba
SHA3-384 hash: cd34d24d7067815e2c74ca2dcb61ba50e908d0c5351d19406c31453e64ead7a96038510d58bdf0fc98b061b8f145fe29
SHA1 hash: 2d697efb0d952408aeff718623ca1ff6ffeaf46e
MD5 hash: 60a1639091b2b6e932dc168e470efb9f
humanhash: nineteen-bacon-music-eight
File name:PT-JAYA NEW ORDER-40.zip
Download: download sample
Signature AgentTesla
File size:577'234 bytes
First seen:2020-07-13 06:39:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:tZUPQR6Zw9bRGiWvD/kgxbn/CZdwF0FTrXjICMfiuyPUDaT73s0ppSPa:tZUPnw/G7bdsU0deiufDaTDJf4a
TLSH 56C423E0D4053607A360B1F8369F859B278DB6E40CD7E0C8DF416DE669D2FE7891928D
Reporter abuse_ch
Tags:AgentTesla Endurance zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 142-4-22-49.unifiedlayer.com
Sending IP: 142.4.22.49
From: Tropical foods Ltd <sales2@nvdseafood.com.vn>
Reply-To: sales2@nvdseafood.com.vn
Subject: New Order Container 40 Feet For Your Products / Ship To Australia,
Attachment: PT-JAYA NEW ORDER-40.zip (contains "PT-JAYA NEW ORDER-40.exe")

AgentTesla SMTP exfil server:
smtp.shyuanhzimeng.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-13 06:41:06 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b45f861c30587affe7bb511db60eab13d2f848ffffd56e4fb04c8137395caeba

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments