MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ed4c91361c0af6e2967ca18bc4877139d068271820a12c04af1d2119eeb89d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7ed4c91361c0af6e2967ca18bc4877139d068271820a12c04af1d2119eeb89d3
SHA3-384 hash: 4cae6889540323df510d32aecc65576bb679af5ed2e9ddc925441b6d776d633899b31f6b8dbc0a119a67b9c5b8831640
SHA1 hash: bd1118d87b596ddc09e11a9793b7864f9c9622f5
MD5 hash: 27f0fd8d386cae75388c35da82022c69
humanhash: bacon-aspen-delta-grey
File name:Halkbank_Ekstre_20200410_080918_330462.rar
Download: download sample
Signature AgentTesla
File size:348'818 bytes
First seen:2020-05-08 12:52:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:05nf8bB63GfJim6I4D0QaVGkxJwd1kjgrbQUjaH6iksBpn:05EbBVOAVG//kjKbQUjxiz9
TLSH 6874238EE4639AB54A914A55018F9DD031420F58D6302FB2B5A257FD7F3E36EA01EECC
Reporter abuse_ch
Tags:AgentTesla geo Halkbank rar TUR


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mono.avnam.net
Sending IP: 190.210.186.210
From: Türkiye İş Bankası A.Ş. <halkbank.e-ekstre@halkbank.com.tr>
Reply-To: noreply@ileti.isbank.com.tr
Subject: İş Bankası-06.05.2020 Numaralı Vadesiz Hesap - TL/USD Özeti
Attachment: Halkbank_Ekstre_20200410_080918_330462.rar (contains "Halkbank_Ekstre_20200410_080918_330462.exe")

AgentTesla SMTP exfil server:
smtp.ionos.es:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-08 13:35:38 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
12 of 48 (25.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 7ed4c91361c0af6e2967ca18bc4877139d068271820a12c04af1d2119eeb89d3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments