MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a97fa4a5be8ad5b0cef2dccb8ab37df72f209853f69973c0a0a155540675fc01. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | a97fa4a5be8ad5b0cef2dccb8ab37df72f209853f69973c0a0a155540675fc01 |
|---|---|
| SHA3-384 hash: | 30c5c1b43345738b3e4c0e12a25b7935511dc1300d8041418e8679c096b1638de312bbef86f41d9db05263a5cd90bbfa |
| SHA1 hash: | 7400223766822946cdc8cbe49373e428176aea8d |
| MD5 hash: | d2c692bd089c03e1d69e210c1d535701 |
| humanhash: | massachusetts-neptune-blue-missouri |
| File name: | FedEx_Aug 2020 at 1.21_8BZ290_PDF.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'245'184 bytes |
| First seen: | 2020-08-04 15:23:22 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 6144:nHAgbCa8sGQTTmXcmff7vP0GPnIiS4fhAkANf3WrSh/leplyT:nHX8kTKXcmffTP9PnI++NUSpaYT |
| TLSH | 1645292E3A83A40AD93D0E3584F959D16771B6573B12CB0F79CA079C6F0269F3B0719A |
| Reporter | |
| Tags: | AgentTesla FedEx img |
abuse_ch
Malspam distributing AgentTesla:HELO: server2.dnsired.com
Sending IP: 144.76.198.243
From: FedEx Support Delivery <shipment@fedex.com>
Subject: RE: Shipment delivery problem #00000964421
Attachment: FedEx_Aug 2020 at 1.21_8BZ290_PDF.img (contains "FedEx_Aug 2020 at 1.21_8BZ290_PDF.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-04 15:25:05 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.