MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1409077a2da04a44691369ce85eba911b405c21cc49c0b13f7fe2c3a9c3db90c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1409077a2da04a44691369ce85eba911b405c21cc49c0b13f7fe2c3a9c3db90c
SHA3-384 hash: 612c99d1fd691cb6248010d263217c0e42b2c6cef551092857d98a9065199d2bfbcf7106d16c200d39c2308b6660b734
SHA1 hash: 4a2a636a43b48165bc790226aa71003f0707fa73
MD5 hash: 4c072ce07dc2db184a92acfbfce03b80
humanhash: twenty-asparagus-dakota-asparagus
File name:SWIFT.rar
Download: download sample
Signature AgentTesla
File size:423'693 bytes
First seen:2020-05-23 11:18:55 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:QuUgg3KhZkQpxePLWXcBebmu5QZjv9b/gPyybX:3Zg3KhZkQpxePL79Mc5/1y7
TLSH 5094233E4FE034ED7F6A7643A476F0C8220D9707D37821D956E8DA22A55890B1DEE93C
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: "mBank S.A." <powiadomienia@mbank.pl>
Subject: mBank S.A. - transaction confirmation
Attachment: SWIFT.rar (contains "SWIFT.exe")

AgentTesla SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-22 22:01:15 UTC
File Type:
Binary (Archive)
Extracted files:
264
AV detection:
15 of 47 (31.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 1409077a2da04a44691369ce85eba911b405c21cc49c0b13f7fe2c3a9c3db90c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments