MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f4f6eb511e3968c7473d795f816224ce53bdaff081d87e8399e6efdcab42173. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4f4f6eb511e3968c7473d795f816224ce53bdaff081d87e8399e6efdcab42173
SHA3-384 hash: 91d397f305c0ffa8c60d11ce60a122fe1fd664d215e2df5be1aa34074aa5bd41441997db79e00436ee91f0d0a51390fa
SHA1 hash: f1766e13838f8d5afe58c0c7b14b61c7b3109fe5
MD5 hash: a747b9559e2a63f7216cb36b37d64b52
humanhash: diet-sierra-maine-blue
File name:PURCHASE REQUISITION.rar
Download: download sample
Signature AgentTesla
File size:526'311 bytes
First seen:2020-08-27 05:38:32 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:mv4wetbhmWvmWHAsAKcWx87HyVOwDlc3WUwHqoCN:mv49s6mXicWWryVOmlc3wCN
TLSH E0B42361375A000C39F258782ED3D923783F89F6FE973682F12FADB51AA875A550235C
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.com
Sending IP: 103.99.3.13
From: MITESH AUTO INDIA PVT LTD <Mitesh@mail.com>
Subject: FWD: QUOTATION
Attachment: PURCHASE REQUISITION.rar (contains "PURCHASE REQUISITION.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-27 05:27:25 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 4f4f6eb511e3968c7473d795f816224ce53bdaff081d87e8399e6efdcab42173

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments