MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 970c4fa87fa25321d0c21249ef8eae46ab39061b3839266b49874e754c24d146. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 970c4fa87fa25321d0c21249ef8eae46ab39061b3839266b49874e754c24d146
SHA3-384 hash: 4ab755de36cc63f383d691c03d4f81cb191f18edd2d2399d06728464f7307934cf160cec65d205926418ffb542aba4df
SHA1 hash: 85eddb2e153391b95b920447fd4741c527e0f411
MD5 hash: f0714637753e9138f2b4119fb5e46086
humanhash: stairway-saturn-seventeen-artist
File name:Scan docs.rar
Download: download sample
Signature AgentTesla
File size:527'820 bytes
First seen:2020-06-19 08:26:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:R3epevJWiIWxP4UHyB5oOcsXHuYfnCkVL4lLKQhSZvcO9qBdiG3:gpqJWiVxP4UHyB5NcslfnCkViWKlnn3
TLSH 7CB4238230F9C4F57A3138695CDB9ED4782D0FE64FA1116DC02562F7991E298AB8FF44
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mesonjulian.com
Sending IP: 45.143.222.124
From: Amy Dai <contacto@mesonjulian.com>
Subject: Re: Remain payment US$15,183.35. of PO 3153485 - T/T NO. DFNO11728911166CTB
Attachment: Scan docs.rar (contains "Scan docs.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-19 08:28:04 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 970c4fa87fa25321d0c21249ef8eae46ab39061b3839266b49874e754c24d146

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments