MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bfbbee95c6b46efe48f560a4ac146802cc173284f6720a8170959c1817e74ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2bfbbee95c6b46efe48f560a4ac146802cc173284f6720a8170959c1817e74ac
SHA3-384 hash: 50c4aba5bb7bf2bf7a059be405dee0a284d34ff83cd5048f9576a5393a10b39fd9d959030d26a1ef64c3b573cb5e3222
SHA1 hash: af37581d4ef70c95fe615517528d32ce4bcd0f16
MD5 hash: 60ccf6f5aee8ea74138edec748112375
humanhash: bluebird-lion-black-october
File name:Carmen Mozzo_pdf.zip
Download: download sample
Signature AgentTesla
File size:343'158 bytes
First seen:2020-10-15 05:11:08 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:J/fwZ0KUlesLZ6lx5dL1Uwiq7t/ZPKH+QqA+gWzIUO/TDfVTjUrrhtYi+pyIO:FfepXiZqbZ5iq7txCsABUkTVTArrhcp6
TLSH 2C7423A57DE23D0BDB64051305ABACC74955E293C09EFD90C4B0AAD1FD58B2833FA396
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Carmen Mozzo<info@nettingpros.com>"
Received: "from nettingpros.com (unknown [185.125.204.39]) "
Date: "14 Oct 2020 20:20:39 -0700"
Subject: "Carmen Mozzo Order Inquiry"
Attachment: "Carmen Mozzo_pdf.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-15 01:20:20 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2bfbbee95c6b46efe48f560a4ac146802cc173284f6720a8170959c1817e74ac

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments