MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 791a1952802fb90ab83d9644b7c34783e2081144ef9511476060abe50b867f3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 791a1952802fb90ab83d9644b7c34783e2081144ef9511476060abe50b867f3c
SHA3-384 hash: 36315633e0e45433be9d033feddedd058ddd386a0332da587243848422f3bc7fc5fa4e6df9cb5fba6bd09d8f8fc2551c
SHA1 hash: 831eeb674e68759363d3d6109e0f51a04492394f
MD5 hash: 9756289d21773a4aa80a20bbb4ca43e2
humanhash: don-uniform-moon-magnesium
File name:New Shipment nvoice No..zip
Download: download sample
Signature AgentTesla
File size:427'726 bytes
First seen:2020-09-21 11:02:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:EaEYEMpCPhoXnEkHWgjdG4bC6LAWgFPBdmmBydBqnTorpFVBcoseun7wrBbVrLmY:tEY2c7jA4b4Wgd+mBydBhnzseu7KBlvj
TLSH F59423C7905AFD02BC6CF89E05A009CB943790527D75827AFD197E446E6CCAB218E36B
Reporter cocaman
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-09-21 10:21:20 UTC
File Type:
Binary (Archive)
Extracted files:
56
AV detection:
34 of 47 (72.34%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 791a1952802fb90ab83d9644b7c34783e2081144ef9511476060abe50b867f3c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments