MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f90acd14d8fe024146b470c42a1cf95abc938e8a2be60e0e1ed124787a9363b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f90acd14d8fe024146b470c42a1cf95abc938e8a2be60e0e1ed124787a9363b7
SHA3-384 hash: 38bc612de99029adeecdd0397911087452d115f730d28dd61bd633020b672c4848ad0e581787dcc1012940278445f52f
SHA1 hash: c98300d4cf174e7e1f9776b3b6809018b210794d
MD5 hash: d4282dd57339d232153c8273f0b24a69
humanhash: freddie-stairway-undress-pennsylvania
File name:Purchase order B1-20003516.zip
Download: download sample
Signature AgentTesla
File size:402'972 bytes
First seen:2020-07-22 08:36:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:nKeMc7jciX2fR8yXxj2584RhRVTAF5J0qF59w/igDrqtbsIeNHPwD3VMcY31:n9jA8yBaGSUF5+qFs7DOtbsIsk3ZY31
TLSH 7584236737963320CBD9A6B8693BCD30DB41220BC4F85CE6EEBF0B9EC194649157C602
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: vps.cinderllafashion.com
Sending IP: 45.95.169.119
From: 銅鑼生產計畫課-吳彥瑤 Nina <nina@pahsco.com.tw>
Subject: Purchase order B1-20003516 (銅鑼紙器).
Attachment: Purchase order B1-20003516.zip (contains "nAzwCl5JbgDN9JQ.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-22 08:37:10 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f90acd14d8fe024146b470c42a1cf95abc938e8a2be60e0e1ed124787a9363b7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments