MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c41115601a53737c376d1dc1da83bc2a8d4acb832cc3f149aacdf10d92b29095. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c41115601a53737c376d1dc1da83bc2a8d4acb832cc3f149aacdf10d92b29095
SHA3-384 hash: 67948b4e3fe700bec7b1e71d6815ead070160a20d940b604c6303c6ee9a239390203442c1af5d64b040a74fe1a5a229f
SHA1 hash: ad527e7d57355636c5b7db33afdf8add51810f8c
MD5 hash: 13449b3e46e0d83024aa78db813f1a5e
humanhash: undress-floor-table-sad
File name:PO 20856200 OLEO FLEX PDF .rar
Download: download sample
Signature AgentTesla
File size:353'807 bytes
First seen:2020-08-18 10:26:41 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:QIogZzXa2WxAota2Ul/e42Wu72AAsxdaltnl9rQiJk0JvB9m0OHzi+0kVmBn:fK2WxVa2UliRqA7OVlBk0JvPmnTmCmBn
TLSH F77423CCD84442B64DC51DB321CBE9BEEB7C229491A65C57A87376088690E90FF3E35B
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vepo.donoralpha.com
Sending IP: 111.118.214.86
From: Nelson Jerez <adquisiciones@oleoflex.cl>
Subject: PO 20856200 OLEO FLEX
Attachment: PO 20856200 OLEO FLEX PDF .rar (contains "PO 20856200 OLEO FLEX PDF .exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-18 10:28:10 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c41115601a53737c376d1dc1da83bc2a8d4acb832cc3f149aacdf10d92b29095

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments