MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7fd0b339ba2848308a68af071d8b825d10deda1a7da6c40329a79173ff86f4fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7fd0b339ba2848308a68af071d8b825d10deda1a7da6c40329a79173ff86f4fc
SHA3-384 hash: b83634a2a71120a0ec595df8db0e5cd0c0560892875e48800a5925a37a6a2234f61c94a3471bf68b7edf2862e311bc50
SHA1 hash: 48873f074c5f8fa66574f4068fbb9be4b4b30072
MD5 hash: c3c8a73b071e12ab091b5cba6f6368c4
humanhash: south-alaska-batman-butter
File name:Rv Quotation_Request_Sheet.pdf.zip
Download: download sample
Signature AgentTesla
File size:442'662 bytes
First seen:2020-06-04 12:29:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:uJXDlnMrSmkjmh6I+4GNijvRiGIJ8FqyP9Tlq85kY76wxrd9kkqpFMpukA6GX:KDlnMBnJnvUGIJUqMZr76OkFpFtkA6q
TLSH 089423BBFCF166926B03BB0CC16F24652EEFBF440850B534A570D0165968F9FACA4A17
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: eldorado.com.uy
Sending IP: 209.58.149.73
From: vplada@eldorado.com.uy
Subject: Re: Quotation_Request_Sheet
Attachment: Rv Quotation_Request_Sheet.pdf.zip (contains "Rv Quotation_Request_Sheet.pdf.bat")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 12:35:26 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 7fd0b339ba2848308a68af071d8b825d10deda1a7da6c40329a79173ff86f4fc

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments