MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92efd150d580940355f5bba85810786d35e40f99512fc9566c9de07f269b6272. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92efd150d580940355f5bba85810786d35e40f99512fc9566c9de07f269b6272
SHA3-384 hash: 023df7ea7f7f1341744372427c188a8220d76d1159814fbf28cefe75b775afc5a24560a10143af1661074e90a05b01c5
SHA1 hash: 23ff806d28fe90a1063c30eacfe1dafed207f4b0
MD5 hash: 436108e8c220790a0813137caaafb340
humanhash: emma-video-oranges-seventeen
File name:payment against your invoice.zip
Download: download sample
Signature AgentTesla
File size:419'387 bytes
First seen:2020-06-25 13:21:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:EQRBswl6uwjbU0u7gQ6q6hwZIHVPTM60pjr6OVQtP/0bM18efe6kgVUQ70ms9KTG:Ei8k0u7gDJhwZIFTz0B0Z8CbTV77m9+w
TLSH 959423D2B963CD10DC020C7FA3D9E964E1452115589D6BAAF4B1BE7D863BC8D2FE88D0
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: seo.seoera.net
Sending IP: 192.254.138.161
From: Chu Lam Yiu <fufei-exhaust@umiail.hinet.net>
Reply-To: wavres9011@gmail.com
Subject: 形式发票"MG_20200625_0001
Attachment: payment against your invoice.zip (contains "payment against your invoice.exe")

AgentTesla SMTP exfil server:
mail.saharaexpress.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-25 10:58:45 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 92efd150d580940355f5bba85810786d35e40f99512fc9566c9de07f269b6272

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments