MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f3a434fcf5f20846c63933401d7a8836fbbbc6fddc5cb3f5d298dbc5ddc4d39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7f3a434fcf5f20846c63933401d7a8836fbbbc6fddc5cb3f5d298dbc5ddc4d39
SHA3-384 hash: 5e9e524ebe3774c95da5b71db25bbbc39df08a4ceaf08b0621b03a1836001eff0381e3bf92f77eeaba07f0d45b0fc981
SHA1 hash: 22c737ca9061a2d0170161244d6463bfa63d9119
MD5 hash: 4cc220933a397a218788ada8dbb76fca
humanhash: louisiana-golf-venus-pizza
File name:SAUDI ARAMCO 2.rar
Download: download sample
Signature AgentTesla
File size:514'605 bytes
First seen:2020-08-19 10:12:20 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:JCo56D8rwg8NnFJrl1luiAZ1XrjYKP58IkjZ8IPBXrH+F7GCYy64H:Ao56Irw1fl11aYO5bUuIPNHs7Gx0H
TLSH 7FB4231454CF69F1DE7A3656CABC8AF52C0E693F40782354A3625B6A5314ECD2B8FCC2
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: 707.zazomika.ml
Sending IP: 157.245.103.60
From: Ludovic,Phan <ludovic.phan@conductix.com>
Subject: RE: PO20200818,PO20200818A,PO20201808B COND
Attachment: SAUDI ARAMCO 2.rar (contains "SAUDI ARAMCO 2.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-18 20:46:59 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 7f3a434fcf5f20846c63933401d7a8836fbbbc6fddc5cb3f5d298dbc5ddc4d39

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments