MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bcc8e29465ff91d16fca5f9b72ad6404abf21f024de77532f5c64763622f066. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0bcc8e29465ff91d16fca5f9b72ad6404abf21f024de77532f5c64763622f066
SHA3-384 hash: 05e2d12865aa711d03ced1ef1ac238b3615e0f79e9977718d4a31b46e7240a0509a0696b6e370258beaa17f060a28f23
SHA1 hash: f45fd379d0ed96abc653afe6877dfc8310bb675c
MD5 hash: f183f831985f8d47165240b219676f42
humanhash: nitrogen-rugby-wyoming-twenty
File name:Swift_Copy.zip
Download: download sample
Signature AgentTesla
File size:431'025 bytes
First seen:2020-07-08 09:00:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:9O1DW8zci1Yr/F7hVMuJkBE203pAZALJ6aIV2pBC7y:c1DW8zci1YB9VMuOBDyHLJ1IVy
TLSH 1A9423C777F2C387B0E5461D6298AC275DFAB998F277F900143BF9223299D624B92C44
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail.hsbcnet.hsbc.com
Sending IP: 102.32.96.94
From: Julie Ann Provido <advising.service.13297394.860428.2953496774@mail.hsbcnet.hsbc.com>
Subject: Swift Copy - Swift Ref:[GLV708037169] / Priority payment / Customer Ref:[PAYMENT NO-36309]
Attachment: Swift_Copy.zip (contains "Swift_Copy.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DelfFareIt
Status:
Malicious
First seen:
2020-07-08 09:02:04 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0bcc8e29465ff91d16fca5f9b72ad6404abf21f024de77532f5c64763622f066

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments