MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4cc212b185d4a8612d5a51b627dce9aaebc457c856cc81869b5c984b46bd186b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4cc212b185d4a8612d5a51b627dce9aaebc457c856cc81869b5c984b46bd186b
SHA3-384 hash: 55f045b21b36c82d57fc22e094407f821de6faad5d835d23ba049f887080a0b58b5a964d06cd5c7daf7a2ae954d4c1c7
SHA1 hash: 7223fa33d3e9044296e34373541e7c17fb4ef48b
MD5 hash: 51fb85c7312dd3bc7a0f7d59a28985a2
humanhash: quebec-cola-crazy-nineteen
File name:Akbank Hesap Özetiniz.pdf.r00
Download: download sample
Signature AgentTesla
File size:449'992 bytes
First seen:2020-05-08 12:51:18 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:Rd0Oe4xABpQ9r/jvOCM4iQCugShMLftZ9Z6nR:jOgcpQ9r/APxTVZM
TLSH 02A423801EAF0DD4EC6B84A815768E1BFDD330F624135E5BBB3911BF27D2128A0BE255
Reporter abuse_ch
Tags:AgentTesla Akbank geo r00 TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: correo.sentidocomun.es
Sending IP: 54.217.206.198
From: AKBANK <hizmet@bilgi.akbank.com>
Subject: Akbank Hesap Özetiniz (Ref:18852\x0a\x0932368)
Attachment: Akbank Hesap Özetiniz.pdf.r00 (contains "Akbank Hesap Özetiniz.pdf.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-08 13:35:36 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 4cc212b185d4a8612d5a51b627dce9aaebc457c856cc81869b5c984b46bd186b

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments