MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 183982a5974d32b8fc68de82394fad87a186eb19b361715bc9c24846bfb2daed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 183982a5974d32b8fc68de82394fad87a186eb19b361715bc9c24846bfb2daed
SHA3-384 hash: 5b11e9172156ec2ca4f877c5b83577ec377fc720c7a30ccd6cbeac7ae4b492d022b573b34c38b071d4afb6d0c5315205
SHA1 hash: 16e42c5850195b1f964af6ce3d79d1738586fb04
MD5 hash: 1a07ee49fcfa27d24acf07d523368060
humanhash: green-mountain-crazy-enemy
File name:Ticari Hesap Özetiniz.rar
Download: download sample
Signature AgentTesla
File size:378'400 bytes
First seen:2020-07-03 06:30:30 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:IiUIuw3SCCTCqGYK7Ppg8BSZBmRKo1kwy/HIb/IHjYoADrjX7DWYkAQOdnp0:XVuwiCCTwYKjdRKmHaHyoAz/kA9A
TLSH EB8423FD23E0A6F170C55999E23A174173B208F48B92864D1A7C4DFB98153137EE2B6E
Reporter abuse_ch
Tags:AgentTesla Akbank geo rar TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: ns295.tekrom.com
Sending IP: 5.10.69.58
From: Akbank Ticari Bankacılık <ticaribankacilik@bilgi.akbank.com>
Subject: HAZİRAN 2020 Ticari Hesap Özetiniz (Ref:2053878463)
Attachment: Ticari Hesap Özetiniz.rar (contains "Ticari Hesap Özetiniz.exe")

AgentTesla SMTP exfil server:
mail.vinorema.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-03 06:32:04 UTC
AV detection:
13 of 28 (46.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 183982a5974d32b8fc68de82394fad87a186eb19b361715bc9c24846bfb2daed

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments