MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f6dba80820037796e17e05263080f6cc482c826dd4b34cec5a1e89ab0fea9710. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f6dba80820037796e17e05263080f6cc482c826dd4b34cec5a1e89ab0fea9710
SHA3-384 hash: 331e3c067c59136413877c80852c3c97d76590fc2f0c4943e20e7e940d2aa274b754ab5a38c9f21df2eda7424ed1c21f
SHA1 hash: 415214f99c40b5a0bb81e46ce2de20d1f79c1f78
MD5 hash: ad0b7367fe233b119044c94e40d90f66
humanhash: freddie-early-four-alpha
File name:PEDIDO4965832-pdf.7z
Download: download sample
Signature AgentTesla
File size:333'158 bytes
First seen:2020-08-13 14:06:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:6ghlMmjHBoUFh/Q6s87RZgbKRus/MATP4x0MZXZmC+xHn8KK/TJ3rtIGMgNg:6Mjhph/Q6smmORX/MuP4x0w4H87/5eGM
TLSH F86423CD754CD528EC2A7C5F233B45CCBF43DBA149A41A0C7865A5E7BBA29386DE1230
Reporter abuse_ch
Tags:7z AgentTesla


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: linux1537.grserver.gr
Sending IP: 185.138.42.92
From: Penka Tzolova <p.tzolova@qualityintergroup.com>
Reply-To: Penka Tzolova <baeutyslondon@yahoo.com>
Subject: NUEVO PEDIDO (POR FAVOR COTIZAR)
Attachment: PEDIDO4965832-pdf.7z (contains "PEDIDO#4965832-pdf.exe")

AgentTesla FTP exfil server:
ftp.transdealer.cl:21

AgentTesla FTP exfil user name:
neworiginlogs@transdealer.cl

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-13 14:08:06 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f6dba80820037796e17e05263080f6cc482c826dd4b34cec5a1e89ab0fea9710

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments