MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2bfbbee95c6b46efe48f560a4ac146802cc173284f6720a8170959c1817e74ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 2bfbbee95c6b46efe48f560a4ac146802cc173284f6720a8170959c1817e74ac |
|---|---|
| SHA3-384 hash: | 50c4aba5bb7bf2bf7a059be405dee0a284d34ff83cd5048f9576a5393a10b39fd9d959030d26a1ef64c3b573cb5e3222 |
| SHA1 hash: | af37581d4ef70c95fe615517528d32ce4bcd0f16 |
| MD5 hash: | 60ccf6f5aee8ea74138edec748112375 |
| humanhash: | bluebird-lion-black-october |
| File name: | Carmen Mozzo_pdf.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 343'158 bytes |
| First seen: | 2020-10-15 05:11:08 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:J/fwZ0KUlesLZ6lx5dL1Uwiq7t/ZPKH+QqA+gWzIUO/TDfVTjUrrhtYi+pyIO:FfepXiZqbZ5iq7txCsABUkTVTArrhcp6 |
| TLSH | 2C7423A57DE23D0BDB64051305ABACC74955E293C09EFD90C4B0AAD1FD58B2833FA396 |
| Reporter | |
| Tags: | AgentTesla zip |
cocaman
Malicious email (T1566.001)From: "Carmen Mozzo<info@nettingpros.com>"
Received: "from nettingpros.com (unknown [185.125.204.39]) "
Date: "14 Oct 2020 20:20:39 -0700"
Subject: "Carmen Mozzo Order Inquiry"
Attachment: "Carmen Mozzo_pdf.zip"
Intelligence
File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-15 01:20:20 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
21 of 48 (43.75%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.