MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f7acb4ce6a3564140577256c6991a4115ea4f61c665310acba3bcd09e1bbb7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3f7acb4ce6a3564140577256c6991a4115ea4f61c665310acba3bcd09e1bbb7d
SHA3-384 hash: 32d86a8a7cca0806ce876c0e48b0798769123fa7dff3f59334f4b1303ec0f1e9179d40548fd3fe00477010f7335fb31a
SHA1 hash: 13675e8d6785888347179ea7d4c4423b7e29d03a
MD5 hash: 8f238d421ea4c5ce6f327b76994833fd
humanhash: mockingbird-earth-floor-five
File name:SWIFT-EUR 43750.PDF.cab
Download: download sample
Signature AgentTesla
File size:284'066 bytes
First seen:2020-06-24 05:41:55 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:74EMIR9iVIndSwxrBM4Ai36BuWP0zaQhe1tN7mPnXcjiIHq6/nsnNE:73Rs2dvxq4AbBbPARhOL7mPcjiQ/sNE
TLSH 625422EE96190F6C3848340FBFD9D8A6F6CC2DED16491B37AA5B129111085CACEC279D
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: "International payments department" <jozo.kalem@rudar.hr>
Subject: Fwd: SWIFT
Attachment: SWIFT-EUR 43750.PDF.cab (contains "SWIFT-EUR 43750-PDF.exe")

AgentTesla SMTP exfil server:
mail.baslog.rs:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-24 04:23:24 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 3f7acb4ce6a3564140577256c6991a4115ea4f61c665310acba3bcd09e1bbb7d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments