MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7511324a45cb3d26fad3d5b32eee333653679e1a725926e7a8fac79d64e37604. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7511324a45cb3d26fad3d5b32eee333653679e1a725926e7a8fac79d64e37604
SHA3-384 hash: d4f449d49edb2175885e8f29c2329f879aa547638808d449255d15a6477f6fb1600ffe142feecf00b20f10d493da4191
SHA1 hash: 7be87bcc0a66f8d4819e7779f05084963128f69f
MD5 hash: cd6f3515ca748d973c4fa4ff92961690
humanhash: michigan-mike-harry-yellow
File name:SWIFT 25.06.2020.pdf_.cab
Download: download sample
Signature AgentTesla
File size:331'386 bytes
First seen:2020-06-25 09:34:16 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:5LUvcYStTqPLKEc/9lhKYnd5M0EieXo29vBkdhsG9lfAvms50AC4Ir9yCb4:JU0YoTqTKEAlhLgXt9/G9zN4ypb4
TLSH DE6423375FFE815A9DE9FE2D306D8F60EE8B0234B534014C459B80BC296745D9E9329A
Reporter abuse_ch
Tags:AgentTesla cab


Avatar
abuse_ch
Malspam distributing AgentTesla:

From: "Marko Jaksic" <servis@ri-petrol.hr>
Subject: Fwd: SWIFT
Attachment: SWIFT 25.06.2020.pdf_.cab (contains "SWIFT 25.06.2020.pdf_.exe")

AgentTesla SMTP exfil server:
mail.baslog.rs:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

cab 7511324a45cb3d26fad3d5b32eee333653679e1a725926e7a8fac79d64e37604

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments