MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67ff4cfecd67b7a1117b8335087755a032e153276de2778230959443aabaf0ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 67ff4cfecd67b7a1117b8335087755a032e153276de2778230959443aabaf0ec
SHA3-384 hash: 38416616f6ba54881997f6aa0f69e50f071b5dadf51c7b29ab2f3b46ab3e8a47d867b1b448801186f8131e7a6483a29d
SHA1 hash: 724061563054202fd84be5cf71ee94ea0140cbb9
MD5 hash: a1707445447ae4755f7aa1c41337d676
humanhash: music-green-texas-low
File name:30% Swift Scan0076567865.zip
Download: download sample
Signature AgentTesla
File size:409'650 bytes
First seen:2020-08-05 11:53:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:uRemu4W75Wam+4JgUyroHz31qJFngqGh5eV3dG:uRemuFA+gDzFQFgqGh5s3E
TLSH 389423E575CBF3D123D64F86C4C4852FE1D835F20EC8863DA8CB8488AEB3854B5185BA
Reporter abuse_ch
Tags:AgentTesla MailChannels zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: anteater.elm.relay.mailchannels.net
Sending IP: 23.83.212.3
From: Rose Gutierrez <sales@sharkmotions.com>
Subject: RV: Advance payment .
Attachment: 30% Swift Scan0076567865.zip (contains "30% Swift Scan0076567865.exe")

AgentTesla SMTP exfil server:
smtp.pharco--corp.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-05 11:55:05 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 67ff4cfecd67b7a1117b8335087755a032e153276de2778230959443aabaf0ec

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments