MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b3ac52d2ffab33fc60a4cd8f7f447e7ca1da2bd224f04b7576efa26641a5291. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9b3ac52d2ffab33fc60a4cd8f7f447e7ca1da2bd224f04b7576efa26641a5291
SHA3-384 hash: c0ee8549c6c9f71fac682f72834fa48a54ac93cce724564105e0488e55408680ba9063d86b6213043f6668d71acc0757
SHA1 hash: 117ab91e509fe15a150e9191fddf05a9b5c65d87
MD5 hash: 5749cd4ab943d3e5120ccfe42eef1492
humanhash: bacon-xray-black-hamper
File name:[1909373834] MT103 Credit.jpg.ace
Download: download sample
Signature AgentTesla
File size:620'337 bytes
First seen:2021-03-04 15:00:42 UTC
Last seen:2021-03-05 10:54:41 UTC
File type: ace
MIME type:application/octet-stream
ssdeep 12288:E15Y/LJgTtLh9q8JuD1uRc4yL6rgirPa/4me3TZofCHWgcC8+:5Tg9q8J81n4yL4g9/4b3FooWgcC8+
TLSH 74D42327EE33F411F64D10E8585E39502236B7F26534B36FA00B20EB77CD5A6899672E
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
5
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2021-03-04 15:01:07 UTC
AV detection:
17 of 49 (34.69%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

ace 9b3ac52d2ffab33fc60a4cd8f7f447e7ca1da2bd224f04b7576efa26641a5291

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments