MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6108a64af7c55a0b83fd99c23ba5b7030ee8d4b04614684d92808757c029d1f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6108a64af7c55a0b83fd99c23ba5b7030ee8d4b04614684d92808757c029d1f3
SHA3-384 hash: a25af8de956f61190c2b1e7a5fc18994b2be55f975e671a36afa22f9965decda7bd1121dbf62e9c4838dbbaa8b349b30
SHA1 hash: 0fda1be6c228400dcdbc0f3f931e114186f46ee2
MD5 hash: b78751e960e41a96e3ace384d79fc7a2
humanhash: undress-avocado-william-arkansas
File name:hesaphareketi00001,pdf.xz
Download: download sample
Signature AgentTesla
File size:366'925 bytes
First seen:2020-07-03 06:18:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:fLM15mVwl8M6DBpGdq62O2jaq1TKY4bbBbwtqizXo0iBsBrdL7eQHaeVvL:TwmVwd+BTB5jKRpQXoOieVD
TLSH BC74237A25DEED5BA852764A61849F84E83C56006037D5F70C3AEF8C10C98ACB52FDE7
Reporter abuse_ch
Tags:AgentTesla geo TUR xz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: garantibbva.com.tr
Sending IP: 45.147.229.205
From: ekstre@garantibbva.com.tr
Subject: Hesap hareketleriniz
Attachment: hesaphareketi00001,pdf.xz (contains "hesaphareketi00001,pdf.exe")

AgentTesla SMTP exfil server:
mail.bunsadokum.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-07-03 06:20:06 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 6108a64af7c55a0b83fd99c23ba5b7030ee8d4b04614684d92808757c029d1f3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments