MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f9b8701049273da231a5bb1db9719c6d027486cdf00e423026760eef84156eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7f9b8701049273da231a5bb1db9719c6d027486cdf00e423026760eef84156eb
SHA3-384 hash: 70fff49c9777f7a1fd672f44692875738da8821287f947172216bd1bf65a37499ad53018dc36bc713188efcc9d8be8a8
SHA1 hash: a3e172dda46af1e7675dcca6279955ab92f7b558
MD5 hash: e706b5202a0b2be50b434f3b9216475d
humanhash: high-equal-snake-violet
File name:Remittance advice.zip
Download: download sample
Signature AgentTesla
File size:315'665 bytes
First seen:2020-07-22 09:18:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:k0fxDlUiUqMUBij6hiPL1EwyWUrquru0rKqsddlB/qdFwNmZ9W0xR:k0fxDPUVUBij6mWwyWSbKqsddP/qXwNs
TLSH D2642372141FA63238BFC66F3272724453DDF688998EC8B82947DD8126F0F266753B25
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: outlook.com
Sending IP: 103.99.1.149
From: Katherine knof <admin@niatec.com.co>
Reply-To: seaninvestments1@outlook.com
Subject: Remittance Advice - Account No. 334030
Attachment: Remittance advice.zip (contains "Remittance advice.exe")

AgentTesla SMTP exfil server:
smtp.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-22 09:20:09 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 7f9b8701049273da231a5bb1db9719c6d027486cdf00e423026760eef84156eb

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments