MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4cf891af524ffb7feb153f8d15c3346b03ba133213f03f2984e4d1c73f0dd03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d4cf891af524ffb7feb153f8d15c3346b03ba133213f03f2984e4d1c73f0dd03
SHA3-384 hash: fccb627ef88b86cb1d5d9f1c011627fb593622568c98ee44aa549338e4b9c4a9f06cebb1245cd6fc6de9e5b0e569d93a
SHA1 hash: b1176161dc2c078c0b31d2197f806440b6254d31
MD5 hash: f1185c7be47c25703bf2ed9c498e1f36
humanhash: bakerloo-burger-winner-ten
File name:New order118809.pdf.img
Download: download sample
Signature AgentTesla
File size:1'572'864 bytes
First seen:2020-08-10 09:29:12 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:IDF/7JJMhRjbSCLU9I2kq9v6M/ZlF40K145B6nnjqKoe:Ip7JCD7no9P/Zcj25EjqKoe
TLSH 0F75C0D371C04876C96B26FBAF0BC2646639FD616D3895063FD82A495FB83913832397
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ns1.prosemvds.com
Sending IP: 89.107.226.195
From: info@gb-promotion.com
Subject: RE: ORDER REQUISITION
Attachment: New order118809.pdf.img (contains "New order#118809.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-10 09:31:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img d4cf891af524ffb7feb153f8d15c3346b03ba133213f03f2984e4d1c73f0dd03

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments