MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0f3ccfa42eaf0810420ea12d83dc79581b10d825f4a25bde919910ab302520f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c0f3ccfa42eaf0810420ea12d83dc79581b10d825f4a25bde919910ab302520f
SHA3-384 hash: 424157630e31e9409de649a3e0cc656a60c8b9dd72ec3a378382d261d6323d3defb96a56b3e7591a58ca5daea28dcd6c
SHA1 hash: eaa9a7bb1bedf66dab08078a08b0035418e0bf1a
MD5 hash: 19066dfee0638bf5e529602be86135c0
humanhash: tennis-johnny-delta-may
File name:Orden de compra.rar
Download: download sample
Signature AgentTesla
File size:578'271 bytes
First seen:2020-08-18 10:06:06 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:oBp3EtyA1HTnOYPqioLocLHlnPc1Wu1rFPOWJ9Oc4y6+NXZ1QmF:kxMhOCwocLFPIP1t9JocZVZ60
TLSH 11C423FF8EC67ABF27FA41D18DD7B15632C1F0D13C393AE6A7939C496AB80119009560
Reporter abuse_ch
Tags:AgentTesla rar Strato


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mo4-p05-ob.smtp.rzone.de
Sending IP: 85.215.255.130
From: e-szamlazas <e-szamlazas@fizetesipont.hu>
Reply-To: e-szamlazas@fizetesipont.hu
Subject: Re; Uitgaande Facturen (F-K99134/20) Kennisgeving
Attachment: Orden de compra.rar (contains "8 17.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.FormBook
Status:
Malicious
First seen:
2020-08-17 23:32:00 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c0f3ccfa42eaf0810420ea12d83dc79581b10d825f4a25bde919910ab302520f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments