MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b023fc4ac93570b1e097a05fffd7517ed9b62a65de5b9c62ea1af1038d0fbab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7b023fc4ac93570b1e097a05fffd7517ed9b62a65de5b9c62ea1af1038d0fbab
SHA3-384 hash: 22e83600ac54347da7db2ed5d3e87db72afa859180b28ef31a433f2c7e0f003dc45e1dedc62bc1942148cb802502c5e2
SHA1 hash: fb33075d5523d2d157f0b1425f69f24b69185862
MD5 hash: 8b4e53b72610411dbebd27e33f7499cb
humanhash: triple-arizona-lake-mexico
File name:Caribglass RFQ 002192.ace
Download: download sample
Signature AgentTesla
File size:480'742 bytes
First seen:2020-06-18 11:14:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:abVpGxhGIHLjsfksJ6fg4DXC2cKmVS+KEKy5AzBYwtwmKRNJxx+z7aM6f+SP9vTY:sVp8efksq/kz10LtMYz0ma9za77gAv
TLSH 6EA423CF15373FA16E4B5D5D017BBA15AE54633CE6D73CBAD9612C480EA20EA1A0D30D
Reporter abuse_ch
Tags:ace AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: oyster.host-care.com
Sending IP: 67.23.226.129
From: Heidi Franklyn <janaka@worldlinkcolombo.net>
Subject: Caribglass RFQ 002192
Attachment: Caribglass RFQ 002192.ace (contains "Caribglass RFQ 002192.bat")

AgentTesla SMTP exfil server:
smtp.mosaiclayouts.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-18 11:36:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 7b023fc4ac93570b1e097a05fffd7517ed9b62a65de5b9c62ea1af1038d0fbab

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments