MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a97fa4a5be8ad5b0cef2dccb8ab37df72f209853f69973c0a0a155540675fc01. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a97fa4a5be8ad5b0cef2dccb8ab37df72f209853f69973c0a0a155540675fc01
SHA3-384 hash: 30c5c1b43345738b3e4c0e12a25b7935511dc1300d8041418e8679c096b1638de312bbef86f41d9db05263a5cd90bbfa
SHA1 hash: 7400223766822946cdc8cbe49373e428176aea8d
MD5 hash: d2c692bd089c03e1d69e210c1d535701
humanhash: massachusetts-neptune-blue-missouri
File name:FedEx_Aug 2020 at 1.21_8BZ290_PDF.img
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-08-04 15:23:22 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:nHAgbCa8sGQTTmXcmff7vP0GPnIiS4fhAkANf3WrSh/leplyT:nHX8kTKXcmffTP9PnI++NUSpaYT
TLSH 1645292E3A83A40AD93D0E3584F959D16771B6573B12CB0F79CA079C6F0269F3B0719A
Reporter abuse_ch
Tags:AgentTesla FedEx img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: server2.dnsired.com
Sending IP: 144.76.198.243
From: FedEx Support Delivery <shipment@fedex.com>
Subject: RE: Shipment delivery problem #00000964421
Attachment: FedEx_Aug 2020 at 1.21_8BZ290_PDF.img (contains "FedEx_Aug 2020 at 1.21_8BZ290_PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-04 15:25:05 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img a97fa4a5be8ad5b0cef2dccb8ab37df72f209853f69973c0a0a155540675fc01

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments