MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f305427ef34fe392a7636dbff4fce6ff8165d17394ae550df616c8306c2c092. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6f305427ef34fe392a7636dbff4fce6ff8165d17394ae550df616c8306c2c092
SHA3-384 hash: fe109fe794899f4f3f02ead5ddf1e28a43136442eecb5ffa624c7c703b285cb2703dce039f8d8a1420aaca04baf64fa5
SHA1 hash: 59a3c8df42dfc4a605e1ea478a6d2ed0431eb395
MD5 hash: 19c83fbc5826f71c03821ba0fe58e5c5
humanhash: december-nuts-illinois-sink
File name:Swift.jpg.ace
Download: download sample
Signature AgentTesla
File size:388'773 bytes
First seen:2021-02-25 05:34:04 UTC
Last seen:2021-02-25 23:33:37 UTC
File type: ace
MIME type:application/octet-stream
ssdeep 6144:sJgEz03KAR3UEK9/yMJMVU+Ed8x/qGNAneKCaAfiZsCM4YaeZTCH7oXFBbzQChVs:sDz03K0kNJ4Ed8xNAneKCPKZVM/TZeUI
TLSH 0A84232DBEB992670CA5B42F061DF412F4673E083328A1DDB9DB5973671D8BF62B4840
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
18
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2021-02-25 03:19:02 UTC
File Type:
Binary (Archive)
Extracted files:
16
AV detection:
13 of 47 (27.66%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

ace 6f305427ef34fe392a7636dbff4fce6ff8165d17394ae550df616c8306c2c092

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments