MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f5c8354926f49d2d86ec199c74ba98b8125b08c4e1ce73d4b71bcb0c160fdb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6f5c8354926f49d2d86ec199c74ba98b8125b08c4e1ce73d4b71bcb0c160fdb6
SHA3-384 hash: 120d9a31ae7d71dd19a4127ac5cc156a8ebdf7ed1cc6f99e8b0d17ada234c0ec89e466db2b609b2935e6020724abc405
SHA1 hash: daab08834a53da8369302f4a830a988cc04edf86
MD5 hash: fe4b72c2d49ad64bffad2100272fb9b1
humanhash: mango-equal-bacon-tennis
File name:Account information.gz
Download: download sample
Signature AgentTesla
File size:400'088 bytes
First seen:2020-07-01 16:10:50 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:Iduqhyy7hPOA/lrWFolCPqaPxkb3O35BLc1q:elyyVvNrWFolnykbMnLc1q
TLSH 808423B352236834F06C67A38948B2C7DEAE87B5E966256CF42D3EACD00F73552D1492
Reporter abuse_ch
Tags:AgentTesla gz HSBC


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail0.701.wongfeixhiou.casa
Sending IP: 139.59.1.174
From: HSBC BANK <noreply@hsbc.co.uk>
Subject: Re: Account details confirmation
Attachment: Account information.gz (contains "gunzipped")

AgentTesla SMTP exfil server:
smtp.elittacop.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-01 16:12:05 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 6f5c8354926f49d2d86ec199c74ba98b8125b08c4e1ce73d4b71bcb0c160fdb6

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments