MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1e9b67b5daba5501fb9a3c613f0eb6ee8058f7548698f7e73ca68f5b585d763. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d1e9b67b5daba5501fb9a3c613f0eb6ee8058f7548698f7e73ca68f5b585d763
SHA3-384 hash: 18d685d0275f8b354175c73c63e14e67a8ac5fc041bac6741372ddfcf76030106b055df4a83dc19a96d0a35ec7d37a67
SHA1 hash: af4e82bb6e1be10a8b98c9b8ba633f6b4f381aff
MD5 hash: 4d244e83fa864b68e0ccd03ac385e95b
humanhash: winner-orange-sink-nuts
File name:STATEMENT OF ACCOUNT.zip
Download: download sample
Signature AgentTesla
File size:467'108 bytes
First seen:2020-08-05 08:40:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:GLGdhSMkV9erSV0vBmrK+ZrSNIakTPWsrs:GLBlvuvBJwuSPhs
TLSH B3A4235449451A440BC9942ABD82CF7D087FD2F22BAC122FB349029EFE7C91589F6777
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: Mrs Christina Khor <Account1@sendmystuffs.com.sg>
Subject: RE: INTERNATIONAL OFFSHORE SOA FOR JULY 2020
Attachment: STATEMENT OF ACCOUNT.zip (contains "STATEMENT OF ACCOUNT.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-05 05:22:32 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d1e9b67b5daba5501fb9a3c613f0eb6ee8058f7548698f7e73ca68f5b585d763

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments