MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c25821c48de85da59b6275be2ef52ad4d4f3f2f1c95fea4cd0afe1430d99ac8d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c25821c48de85da59b6275be2ef52ad4d4f3f2f1c95fea4cd0afe1430d99ac8d
SHA3-384 hash: fdbacdddd69447d44cb8c6f86323ea21e1436ab55664ddc7e0b398c32e2ba6fc81257badb53194b0e42912c842e55061
SHA1 hash: d85fc12aef2db45e2afefc5f68f5bb91345d2503
MD5 hash: 84f854602e10b7604f9d40b15229dc64
humanhash: twelve-blossom-berlin-item
File name:AWB & Shipping Doc.Img.ace
Download: download sample
Signature AgentTesla
File size:500'930 bytes
First seen:2021-02-22 06:28:41 UTC
Last seen:2021-02-26 00:11:40 UTC
File type: ace
MIME type:application/octet-stream
ssdeep 12288:XijpcyvhOO8xHqmfMxn2HzxTS3lfCEqtivizBe:XecypKxHqU0n2HzNS3Uriqs
TLSH 37B4237EC15CE982FC9D6B3FBC98E840C31AD6209517B84E6EE51E51E83281CEB055F9
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
30
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2021-02-21 18:23:44 UTC
AV detection:
17 of 47 (36.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

ace c25821c48de85da59b6275be2ef52ad4d4f3f2f1c95fea4cd0afe1430d99ac8d

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments